LOW · 3.5

CVE-2012-3371

The Nova scheduler in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when DifferentHostFilter or SameHostFilter is enabled, allows remote authenticated users to cause a denial of service...

Vulnerability Description

The Nova scheduler in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when DifferentHostFilter or SameHostFilter is enabled, allows remote authenticated users to cause a denial of service (excessive database lookup calls and server hang) via a request with many repeated IDs in the os:scheduler_hints section.

CVSS Score

3.5

LOW

AV:N/AC:M/Au:S/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
OpenstackCompute2012.2
OpenstackEssex2012.1
OpenstackFolsom2012.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-3371?

CVE-2012-3371 is a vulnerability with a CVSS score of 3.5 (LOW). The Nova scheduler in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when DifferentHostFilter or SameHostFilter is enabled, allows remote authenticated users to cause a denial of service...

How severe is CVE-2012-3371?

CVE-2012-3371 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-3371?

Check the references section above for vendor advisories and patch information. Affected products include: Openstack Compute, Openstack Essex, Openstack Folsom.