Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Fri, 21 Mar 2014 01:39:31 -0400 (EDT)
From: cve-assign@...re.org
To: gmurphy@...hat.com
Cc: cve-assign@...re.org, oss-security@...ts.openwall.com
Subject: Re: CVE request for vulnerability in OpenStack Nova

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

> A vulnerability was discovered in OpenStack
> 
> Title: Nova VMWare driver leaks rescued images
> Products: Nova
> Versions: 2013.2 to 2013.2.2
> 
> By requesting Nova place an image into rescue, then deleting the
> image, an authenticated user my exceed their quota. This can result in
> a denial of service via excessive resource consumption. Only setups
> using the Nova VMWare driver are affected.
> 
> https://bugs.launchpad.net/nova/+bug/1269418

Use CVE-2014-2573.

- -- 
CVE assignment team, MITRE CVE Numbering Authority
M/S M300
202 Burlington Road, Bedford, MA 01730 USA
[ PGP key available through http://cve.mitre.org/cve/request_id.html ]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (SunOS)

iQEcBAEBAgAGBQJTK8/gAAoJEKllVAevmvmsiu4H/AhIpSex25e5aIFfRXAeYlAa
R0KMYye5byjbegThQCx0bzMPCrBS7tj9olEyqrr6BwjsDpVZBPG6LhsCXZzfWqed
ps/gcbGDLuQwUzD+XsmYYKgDi2kmKDmRCgWjlPLel6kUDAIFW1cy9gTYKinJ94e1
SA0zcFTEUh8lCMp9PqeFaqW7qJ7PhvhPi6fGd3Fpxzdd1GPchOnNwBB5XmTQqLW0
MGptSnR6cnJtwfYJfdI73VGCglfr0yW26IoIP9n55FLXTu6meFm8WuCIVXa84Xeh
rSHLdO0ptX9YkJX+2pHepdx/kLH1w/8Yz1++EZZ7bViYXvh2E6Fgb5f44lhXajM=
=CeDI
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.