4.9
CVSSv2

CVE-2012-3447

Published: 20/08/2012 Updated: 07/11/2023
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
VMScore: 436
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:P

Vulnerability Summary

virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x prior to 2012.1.2 and Folsom before Folsom-3 allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image that uses a symlink that is only readable by root. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3361.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack nova 2012.1

openstack folsom

Vendor Advisories

Debian Bug report logs - #684256 CVE-2012-3447: file injection writing to host filesystem Package: nova; Maintainer for nova is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Thomas Goirand <zigo@debianorg> Date: Wed, 8 Aug 2012 04:21:02 UTC Severity: critical Found in version 201211-5 Fixed ...
Nova could be made to overwrite or corrupt arbitrary files in the compute host file system ...