PT-2018-6722 · Openstack+2 · Openstack Nova+2
Lee Yarwood
·
Publicado
2018-02-19
·
Atualizado
2023-02-13
·
CVE-2017-18191
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
OpenStack Nova versions 15.x through 15.1.0
OpenStack Nova versions 16.x through 16.1.1
Description:
An issue in OpenStack Nova allows an attacker to access the underlying raw volume and corrupt the LUKS header by detaching and reattaching an encrypted volume. This results in a denial of service attack on the compute host. All Nova setups that support encrypted volumes are affected.
Recommendations:
For OpenStack Nova versions 15.x through 15.1.0, update to a version that fixes the issue to prevent denial of service attacks.
For OpenStack Nova versions 16.x through 16.1.1, update to a version that fixes the issue to prevent denial of service attacks.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linuxmint
Openstack Nova
Ubuntu