CVE-2013-4469
Published Nov 2, 2013
Last updated a year ago
Overview
- Description
- OpenStack Compute (Nova) Folsom, Grizzly, and Havana, when use_cow_images is set to False, does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) by transferring an image with a large virtual size that does not contain a large amount of data from Glance. NOTE: this issue is due to an incomplete fix for CVE-2013-2096.
- Source
- secalert@redhat.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 1.9
- Impact score
- 2.9
- Exploitability score
- 3.4
- Vector string
- AV:L/AC:M/Au:N/C:N/I:N/A:P
Weaknesses
- nvd@nist.gov
- CWE-399
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:openstack:folsom:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F5BA13BC-F088-45AA-AD10-B74F89CE5375" }, { "criteria": "cpe:2.3:a:openstack:grizzly:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A83ED744-9E3D-4510-B3E6-6DDE1090F0B7" }, { "criteria": "cpe:2.3:a:openstack:havana:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "77522028-683C-4708-AF46-50B49A0A2D15" } ], "operator": "OR" } ] } ]