Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Ubuntu 13.10 USN-2000-1 Moderate: Nova DoS from Network Requests

ubuntu
Calendar Grey October 23, 2013
Scroller Ubuntu
Multiple security vulnerabilities in Nova for Ubuntu could let a malicious user destabilize the system or access sensitive data. Timely updates are recommended
Nova could be made to crash if it received specially crafted network requests.

Summary

Nova could be made to crash if it received specially crafted network

requests.

Software Description:

- nova: OpenStack Compute cloud infrastructure

Details:

It was discovered that Nova did not properly enforce the is_public property

when determining flavor access. An authenticated attacker could exploit

this to obtain sensitive information in private flavors. This issue only

affected Ubuntu 12.10 and 13.10. (CVE-2013-2256, CVE-2013-4278)

Grant Murphy discovered that Nova would allow XML entity processing. A

remote unauthenticated attacker could exploit this using the Nova API to

cause a denial of service via resource exhaustion. This issue only

affected Ubuntu 13.10. (CVE-2013-4179)

Vishvananda Ishaya discovered that Nova inefficiently handled network

security group updates when Nova was configured to use nova-network. An

authenticated attacker could exploit this to cause a denial of service.

(CVE-2013-4185)

Jaroslav Henner discovered that Nova did not...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
  python-nova                     1:2013.1.3-0ubuntu1.1

Ubuntu 12.10:
  python-nova                     2012.2.4-0ubuntu3.1

Ubuntu 12.04 LTS:
  python-nova                     2012.1.3+stable-20130423-e52e6912-0ubuntu1.2

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2000-1

CVE-2013-2256, CVE-2013-4179, CVE-2013-4185, CVE-2013-4261,

CVE-2013-4278

Severity
important
Lowest
Low
Medium
High
Critical

=========================================================================Ubuntu Security Notice USN-2000-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.