CVE Vulnerabilities

CVE-2012-3361

Published: Jul 22, 2012 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image.

Affected Software

Name Vendor Start Version End Version
Diablo Openstack 2011.3 (including) 2011.3 (including)
Essex Openstack 2012.1 (including) 2012.1 (including)
Folsom Openstack 2012.2 (including) 2012.2 (including)
Nova Ubuntu natty *
Nova Ubuntu oneiric *
Nova Ubuntu precise *

References