Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5162

Опубликовано: 29 июн. 2015
Источник: redhat
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk consumption) via a crafted disk image.

A resource vulnerability in the OpenStack Compute (nova), Block Storage (cinder), and Image (glance) services was found in their use of qemu-img. An unprivileged user could consume as much as 4 GB of RAM on the compute host by uploading a malicious image. This flaw could lead possibly to host out-of-memory errors and negatively affect other running tenant instances. oslo.concurrency has been updated to support process limits ('prlimit'), which is needed to fix this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)openstack-glanceNot affected
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)openstack-novaWill not fix
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)openstack-glanceNot affected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)openstack-novaWill not fix
Red Hat OpenStack Platform 10 (Newton)openstack-cinderNot affected
Red Hat OpenStack Platform 10 (Newton)openstack-glanceNot affected
Red Hat OpenStack Platform 10 (Newton)openstack-novaNot affected
Red Hat OpenStack Platform 9 (Mitaka)openstack-novaNot affected
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6openstack-cinderFixedRHSA-2017:016519.01.2017
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7openstack-cinderFixedRHSA-2017:015319.01.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1268303openstack-nova/glance/cinder: Malicious image may exhaust resources

EPSS

Процентиль: 87%
0.0359
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk consumption) via a crafted disk image.

CVSS3: 7.5
nvd
больше 9 лет назад

The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk consumption) via a crafted disk image.

CVSS3: 7.5
debian
больше 9 лет назад

The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Gl ...

CVSS3: 7.5
github
больше 3 лет назад

OpenStack Cinder, Glance, and Nova contain Uncontrolled Resource Consumption

EPSS

Процентиль: 87%
0.0359
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2