3.5
CVSSv2

CVE-2012-3371

Published: 17/07/2012 Updated: 24/08/2012
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:N/A:P

Vulnerability Summary

The Nova scheduler in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when DifferentHostFilter or SameHostFilter is enabled, allows remote authenticated users to cause a denial of service (excessive database lookup calls and server hang) via a request with many repeated IDs in the os:scheduler_hints section.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack compute 2012.2

openstack essex 2012.1

openstack folsom 2012.2

Vendor Advisories

Debian Bug report logs - #681301 CVE-2012-3371 Package: nova; Maintainer for nova is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Thu, 12 Jul 2012 08:21:02 UTC Severity: grave Tags: security Fixed in version nova/201211-5 Done: Ghe Rivero ...
Nova could be made to not respond if passed specially crafted input ...