6
CVSSv2

CVE-2013-0335

Published: 22/03/2013 Updated: 05/06/2013
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack essex 2012.1

openstack grizzly 2012.2

openstack folsom 2012.2

canonical ubuntu linux 11.10

canonical ubuntu linux 12.10

canonical ubuntu linux 12.04

Vendor Advisories

Synopsis Moderate: openstack-nova security and bug fix update Type/Severity Security Advisory: Moderate Topic Updated openstack-nova packages that fix two security issues and variousbugs are now available for Red Hat OpenStack FolsomThe Red Hat Security Response Team has rated this update as having moderat ...
Debian Bug report logs - #701773 nova: CVE-2013-0335: VNC proxy can connect to the wrong VM Package: nova; Maintainer for nova is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 26 Feb 2013 22:30:04 UTC Severity: important Tags: security Found in ...
Two security issues were fixed in Nova ...