2.1
CVSSv2

CVE-2013-4463

Published: 06/02/2014 Updated: 07/11/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) via a compressed QCOW2 image. NOTE: this issue is due to an incomplete fix for CVE-2013-2096.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack havana -

openstack grizzly -

openstack folsom -

Vendor Advisories

Synopsis Moderate: openstack-nova security and bug fix update Type/Severity Security Advisory: Moderate Topic Updated openstack-nova packages that fix two security issues and three bugsare now available for Red Hat Enterprise Linux OpenStack Platform 30The Red Hat Security Response Team has rated this upd ...
Several security issues were fixed in OpenStack Nova ...
Debian Bug report logs - #728605 nova: CVE-2013-4463 and CVE-2013-4469 Package: nova; Maintainer for nova is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 3 Nov 2013 14:30:01 UTC Severity: important Tags: patch, security, upstream Fixed in ver ...
Debian Bug report logs - #732022 nova: CVE-2013-7048: Nova live snapshots use an insecure local directory Package: nova; Maintainer for nova is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 12 Dec 2013 16:09:02 UTC Severity: important Tags: secu ...