4
CVSSv2

CVE-2013-1838

Published: 22/03/2013 Updated: 29/08/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a quota for fixed IPs, which allows remote authenticated users to cause a denial of service (resource exhaustion and failure to spawn new instances) via a large number of calls to the addFixedIp function.

Vulnerable Product Search on Vulmon Subscribe to Product

openstack folsom 2012.2

openstack grizzly 2012.2

openstack essex 2012.1

canonical ubuntu linux 11.10

canonical ubuntu linux 12.10

canonical ubuntu linux 12.04

Vendor Advisories

Synopsis Moderate: openstack-nova security and bug fix update Type/Severity Security Advisory: Moderate Topic Updated openstack-nova packages that fix two security issues and variousbugs are now available for Red Hat OpenStack FolsomThe Red Hat Security Response Team has rated this update as having moderat ...
Debian Bug report logs - #703064 CVE-2013-1838: Nova DoS by allocating all Fixed IPs Package: nova; Maintainer for nova is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Thomas Goirand <zigo@debianorg> Date: Thu, 14 Mar 2013 20:51:04 UTC Severity: grave Tags: security Fixed in versions nova/2012 ...
Two security issues were fixed in Nova ...