Upstream information
Description
OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) by creating an image with a large virtual size that does not contain a large amount of data.SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having moderate severity.
National Vulnerability Database | SUSE | |
---|---|---|
Base Score | 2.1 | 4.9 |
Vector | AV:L/AC:L/Au:N/C:N/I:N/A:P | AV:L/AC:L/Au:N/C:N/I:N/A:C |
Access Vector | Local | Local |
Access Complexity | Low | Low |
Authentication | None | None |
Confidentiality Impact | None | None |
Integrity Impact | None | None |
Availability Impact | Partial | Complete |
SUSE Security Advisories:
- SUSE-SU-2013:1292-1, published Fri Aug 2 12:04:09 MDT 2013
SUSE Timeline for this CVE
CVE page created: Mon Jul 15 13:14:18 2013CVE page last modified: Fri Oct 7 12:46:28 2022