Vulnerability Description
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openstack | Essex | 2012.1 |
| Openstack | Folsom | 2012.2 |
| Openstack | Grizzly | 2012.2 |
| Canonical | Ubuntu Linux | 11.10 |
Related Weaknesses (CWE)
References
- http://rhn.redhat.com/errata/RHSA-2013-0709.html
- http://secunia.com/advisories/52337Vendor Advisory
- http://secunia.com/advisories/52728Vendor Advisory
- http://www.openwall.com/lists/oss-security/2013/02/26/7
- http://www.osvdb.org/90657
- http://www.ubuntu.com/usn/USN-1771-1
- https://bugs.launchpad.net/nova/+bug/1125378
- https://review.openstack.org/#/c/22086/
- https://review.openstack.org/#/c/22758
- https://review.openstack.org/#/c/22872/
- http://rhn.redhat.com/errata/RHSA-2013-0709.html
- http://secunia.com/advisories/52337Vendor Advisory
- http://secunia.com/advisories/52728Vendor Advisory
- http://www.openwall.com/lists/oss-security/2013/02/26/7
- http://www.osvdb.org/90657
FAQ
What is CVE-2013-0335?
CVE-2013-0335 is a vulnerability with a CVSS score of 6.0 (MEDIUM). OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM th...
How severe is CVE-2013-0335?
CVE-2013-0335 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-0335?
Check the references section above for vendor advisories and patch information. Affected products include: Openstack Essex, Openstack Folsom, Openstack Grizzly, Canonical Ubuntu Linux.