PT-2013-3539 · Openstack · Openstack Compute
Publicado
2013-07-09
·
Atualizado
2022-05-17
·
CVE-2013-2096
CVSS v4.0
6.9
Média
| Vetor | AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenStack Compute (Nova) versions Folsom through Havana
Description
The issue allows local users to cause a denial of service by creating an image with a large virtual size that does not contain a large amount of data, resulting in host file system disk consumption.
Recommendations
For versions Folsom through Havana, consider restricting the creation of QCOW2 images or implementing size verification to prevent excessive disk consumption until a proper fix is applied.
Correção
Allocation of Resources Without Limits
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Openstack Compute