4
CVSSv2

CVE-2012-1585

Published: 17/08/2012 Updated: 14/11/2018
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

OpenStack Compute (Nova) Essex prior to 2011.3 allows remote authenticated users to cause a denial of service (Nova-API log file and disk consumption) via a long server name.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack nova

Vendor Advisories

Nova log files could be made to exhaust storage resources ...
Debian Bug report logs - #666888 DoS through long server names Package: nova; Maintainer for nova is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Mon, 2 Apr 2012 08:03:02 UTC Severity: grave Tags: security Fixed in version 20121~rc3-1 Done ...