Описание
virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom before Folsom-3 allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image that uses a symlink that is only readable by root. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3361.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 2012.2~f3-0ubuntu1 |
| hardy | DNE | |
| lucid | DNE | |
| natty | ignored | end of life |
| oneiric | released | 2011.3-0ubuntu6.10 |
| precise | released | 2012.1+stable~20120612-3ee026e-0ubuntu1.3 |
| quantal | not-affected | 2012.2~f3-0ubuntu1 |
| upstream | needs-triage |
Показывать по
EPSS
4.9 Medium
CVSS2
Связанные уязвимости
virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom before Folsom-3 allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image that uses a symlink that is only readable by root. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3361.
virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 ...
EPSS
4.9 Medium
CVSS2