Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-2140

Опубликовано: 08 мар. 2016
Источник: redhat
CVSS2: 7.5
EPSS Низкий

Описание

The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images is set to false, allows remote authenticated users to read arbitrary files via a crafted qcow2 header in an ephemeral or root disk.

An information-exposure flaw was found in the OpenStack Compute (nova) resize and migrate functionality. An authenticated user could write a malicious qcow header to an ephemeral or root disk, referencing a block device as a backing file. With a subsequent resize or migration, file system content on the specified device would be leaked to the user. Only setups using libvirt with raw storage and "use_cow_images = False" were affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 8 (Liberty)openstack-novaNot affected
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6openstack-novaFixedRHSA-2016:036608.03.2016
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7openstack-novaFixedRHSA-2016:036508.03.2016
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7openstack-novaFixedRHSA-2016:036408.03.2016
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7openstack-novaFixedRHSA-2016:036308.03.2016

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1313454openstack-nova: Host data leak through resize/migration

EPSS

Процентиль: 70%
0.00634
Низкий

7.5 High

CVSS2

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 10 лет назад

The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images is set to false, allows remote authenticated users to read arbitrary files via a crafted qcow2 header in an ephemeral or root disk.

CVSS3: 5.3
nvd
почти 10 лет назад

The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images is set to false, allows remote authenticated users to read arbitrary files via a crafted qcow2 header in an ephemeral or root disk.

CVSS3: 5.3
debian
почти 10 лет назад

The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) ...

CVSS3: 5.3
github
больше 3 лет назад

OpenStack Nova host data access through resize/migration

EPSS

Процентиль: 70%
0.00634
Низкий

7.5 High

CVSS2