CVE Vulnerabilities

CVE-2015-5162

Published: Oct 07, 2016 | Modified: Feb 13, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu

The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk consumption) via a crafted disk image.

Affected Software

Name Vendor Start Version End Version
Cinder Openstack 7.0.2 (including) 7.0.2 (including)
Cinder Openstack 8.0.0 (including) 8.0.0 (including)
Cinder Openstack 8.1.0 (including) 8.1.0 (including)
Glance Openstack * 11.0.0 (including)
Glance Openstack 11.0.1 (including) 11.0.1 (including)
Glance Openstack 12.0.0 (including) 12.0.0 (including)
Nova Openstack * 12.0.3 (including)
Nova Openstack 13.0.0 (including) 13.0.0 (including)

References