CVE Vulnerabilities

CVE-2015-5162

Published: Oct 07, 2016 | Modified: Feb 13, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
5.3 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM

The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk consumption) via a crafted disk image.

Affected Software

Name Vendor Start Version End Version
Cinder Openstack 7.0.2 (including) 7.0.2 (including)
Cinder Openstack 8.0.0 (including) 8.0.0 (including)
Cinder Openstack 8.1.0 (including) 8.1.0 (including)
Glance Openstack * 11.0.0 (including)
Glance Openstack 11.0.1 (including) 11.0.1 (including)
Glance Openstack 12.0.0 (including) 12.0.0 (including)
Nova Openstack * 12.0.3 (including)
Nova Openstack 13.0.0 (including) 13.0.0 (including)
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 RedHat openstack-cinder-0:2014.1.5-9.el6ost *
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 RedHat openstack-cinder-0:2014.1.5-9.el7ost *
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 RedHat openstack-cinder-0:2014.2.4-11.el7ost *
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 RedHat openstack-cinder-0:2015.1.3-12.el7ost *
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 RedHat openstack-glance-0:2015.1.2-3.el7ost *
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 RedHat openstack-nova-0:2015.1.4-32.el7ost *
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 RedHat python-oslo-concurrency-0:1.8.2-2.el7ost *
Red Hat OpenStack Platform 8.0 (Liberty) RedHat openstack-cinder-1:7.0.3-1.el7ost *
Red Hat OpenStack Platform 8.0 (Liberty) RedHat openstack-glance-1:11.0.1-6.el7ost *
Red Hat OpenStack Platform 8.0 (Liberty) RedHat openstack-nova-1:12.0.5-9.el7ost *
Red Hat OpenStack Platform 9.0 (Mitaka) RedHat openstack-cinder-1:8.1.1-4.el7ost *
Red Hat OpenStack Platform 9.0 (Mitaka) RedHat openstack-glance-1:12.0.0-2.el7ost *
Nova Ubuntu precise *
Nova Ubuntu trusty *
Nova Ubuntu upstream *
Nova Ubuntu vivid *
Nova Ubuntu wily *
Nova Ubuntu yakkety *

References