CVE Vulnerabilities

CVE-2012-3361

Published: Jul 22, 2012 | Modified: Aug 17, 2012
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image.

Affected Software

Name Vendor Start Version End Version
Diablo Openstack 2011.3 (including) 2011.3 (including)
Essex Openstack 2012.1 (including) 2012.1 (including)
Folsom Openstack 2012.2 (including) 2012.2 (including)
Nova Ubuntu natty *
Nova Ubuntu oneiric *
Nova Ubuntu precise *

References