CVE-2011-4596
published 2011-12-23CVE-2011-4596: Multiple directory traversal vulnerabilities in OpenStack Nova before 2011.3.1, when the EC2 API and the S3/RegisterImage image-registration method are…
PriorityP431medium6CVSS 2.0
AVNACMAuSCPIPAP
EPSS
1.94%
77.9th percentile
Multiple directory traversal vulnerabilities in OpenStack Nova before 2011.3.1, when the EC2 API and the S3/RegisterImage image-registration method are enabled, allow remote authenticated users to overwrite arbitrary files via a crafted (1) tarball or (2) manifest.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2012.1~e1-4 (bookworm) | nova 2012.1~e1-4 (bookworm) |
| openstack | nova | >= 0 < 2012.1~e1-4 | 2012.1~e1-4 |
| openstack | nova | >= 0 < 2012.1~e1-4 | 2012.1~e1-4 |
| openstack | nova | >= 0 < 2012.1~e1-4 | 2012.1~e1-4 |
| openstack | nova | >= 0 < 2012.1~e1-4 | 2012.1~e1-4 |
| openstack | nova | >= 0 < 12.0.0a0 | 12.0.0a0 |
| openstack | nova | >= 2011.3 < 2011.3.1 | 2011.3.1 |
CVSS provenance
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv6.0MEDIUM
vendor_debian6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
OpenStack Nova Multiple directory traversal vulnerabilities
osv·2022-05-14
CVE-2011-4596 [MEDIUM] OpenStack Nova Multiple directory traversal vulnerabilities
OpenStack Nova Multiple directory traversal vulnerabilities
Multiple directory traversal vulnerabilities in OpenStack Nova before 2011.3.1, when the EC2 API and the S3/RegisterImage image-registration method are enabled, allow remote authenticated users to overwrite arbitrary files via a crafted (1) tarball or (2) manifest.
GHSA
OpenStack Nova Multiple directory traversal vulnerabilities
ghsa·2022-05-14
CVE-2011-4596 [MEDIUM] CWE-22 OpenStack Nova Multiple directory traversal vulnerabilities
OpenStack Nova Multiple directory traversal vulnerabilities
Multiple directory traversal vulnerabilities in OpenStack Nova before 2011.3.1, when the EC2 API and the S3/RegisterImage image-registration method are enabled, allow remote authenticated users to overwrite arbitrary files via a crafted (1) tarball or (2) manifest.
OSV
CVE-2011-4596: Multiple directory traversal vulnerabilities in OpenStack Nova before 2011
osv·2011-12-23·CVSS 6.0
CVE-2011-4596 [MEDIUM] CVE-2011-4596: Multiple directory traversal vulnerabilities in OpenStack Nova before 2011
Multiple directory traversal vulnerabilities in OpenStack Nova before 2011.3.1, when the EC2 API and the S3/RegisterImage image-registration method are enabled, allow remote authenticated users to overwrite arbitrary files via a crafted (1) tarball or (2) manifest.
Ubuntu
Nova vulnerability
vendor_ubuntu·2011-12-13
CVE-2011-4596 Nova vulnerability
Title: Nova vulnerability
Summary: Nova could be made to overwrite files.
David Black discovered that Nova did not properly perform input validation
during image registration. An attacker could exploit this by registering a
crafted image using the EC2 API or S3/RegisterImage method and overwrite
files as the nova user.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2011-4596: nova - Multiple directory traversal vulnerabilities in OpenStack Nova before 2011.3.1, ...
vendor_debian·2011·CVSS 6.0
CVE-2011-4596 [MEDIUM] CVE-2011-4596: nova - Multiple directory traversal vulnerabilities in OpenStack Nova before 2011.3.1, ...
Multiple directory traversal vulnerabilities in OpenStack Nova before 2011.3.1, when the EC2 API and the S3/RegisterImage image-registration method are enabled, allow remote authenticated users to overwrite arbitrary files via a crafted (1) tarball or (2) manifest.
Scope: local
bookworm: resolved (fixed in 2012.1~e1-4)
bullseye: resolved (fixed in 2012.1~e1-4)
forky: resolved (fixed in 2012.1~e1-4)
sid: resolved (fixed in 2012.1~e1-4)
trixie: resolved (fixed in 2012.1~e1-4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE 2011-4596 openstack-nova: Sanitize EC2 manifests and image tarballs
bugzilla·2011-12-13
[MEDIUM] CVE 2011-4596 openstack-nova: Sanitize EC2 manifests and image tarballs
CVE 2011-4596 openstack-nova: Sanitize EC2 manifests and image tarballs
This just made public upstream:
Prevent potential directory traversal with malicious EC2 image tarballs,
by making sure the tarfile is safe before unpacking it. Fixes bug 894755
Prevent potential directory traversal with malicious file names in
EC2 image manifests. Fixes bug 885167
See also:
https://review.openstack.org/#change,2284
https://bugs.launchpad.net/bugs/cve/2011-4596
Discussion:
Created openstack-nova tracking bugs for this issue
Affects: fedora-16 [bug 767251]
---
openstack-nova-2011.3-13.fc16 has been pushed to the Fedora 16 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE 2011-4596 openstack-nova: Sanitize EC2 manifests and image tarballs [fedora-16]
bugzilla·2011-12-13
[MEDIUM] CVE 2011-4596 openstack-nova: Sanitize EC2 manifests and image tarballs [fedora-16]
CVE 2011-4596 openstack-nova: Sanitize EC2 manifests and image tarballs [fedora-16]
fedora-16 tracking bug for openstack-nova: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
openstack-nova-2011.3-13.el6 has been submitted as an update for Fedora EPEL 6.
https://admin.fedoraproject.org/updates/openstack-nova-2011.3-13.el6
---
openstack-nova-2011.3-14.el6 has been submitted as an update for Fedora EPEL 6.
https://admin.fedoraproject.org/updates/openstack-nova-2011.3-14.el6
---
Package openstack-nova-2011.3-14.el6:
* should fix your issue,
* was pushed to the Fedora EPEL 6 testing repository,
* should be availab
https://bugs.launchpad.net/nova/+bug/885167https://bugs.launchpad.net/nova/+bug/894755https://github.com/openstack/nova/commit/76363226bd8533256f7795bba358d7f4b8a6c9e6https://github.com/openstack/nova/commit/ad3241929ea00569c74505ed002208ce360c667ehttps://lists.launchpad.net/openstack/msg06105.htmlhttps://bugs.launchpad.net/nova/+bug/885167https://bugs.launchpad.net/nova/+bug/894755https://github.com/openstack/nova/commit/76363226bd8533256f7795bba358d7f4b8a6c9e6https://github.com/openstack/nova/commit/ad3241929ea00569c74505ed002208ce360c667ehttps://lists.launchpad.net/openstack/msg06105.html
2011-12-23
Published