CVE-2012-1585
published 2012-08-17CVE-2012-1585: OpenStack Compute (Nova) Essex before 2011.3 allows remote authenticated users to cause a denial of service (Nova-API log file and disk consumption) via a long…
PriorityP414medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
2.07%
79.4th percentile
OpenStack Compute (Nova) Essex before 2011.3 allows remote authenticated users to cause a denial of service (Nova-API log file and disk consumption) via a long server name.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2012-1~rc3-1 (bookworm) | nova 2012-1~rc3-1 (bookworm) |
| openstack | nova | >= 0 < 2012-1~rc3-1 | 2012-1~rc3-1 |
| openstack | nova | >= 0 < 2012-1~rc3-1 | 2012-1~rc3-1 |
| openstack | nova | >= 0 < 2012-1~rc3-1 | 2012-1~rc3-1 |
| openstack | nova | >= 0 < 2012-1~rc3-1 | 2012-1~rc3-1 |
| openstack | nova | >= 0 < 12.0.0a0 | 12.0.0a0 |
| openstack | nova | >= 2011.1 < 2011.3 | 2011.3 |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.0MEDIUM
vendor_debian4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Nova vulnerability
vendor_ubuntu·2012-03-29
CVE-2012-1585 Nova vulnerability
Title: Nova vulnerability
Summary: Nova log files could be made to exhaust storage resources.
Dan Prince discovered that Nova did not properly perform input validation on
the length of server names. An authenticated attacker could issue requests
using long server names to exhaust the storage resources containing the Nova
API log file.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2012-1585: nova - OpenStack Compute (Nova) Essex before 2011.3 allows remote authenticated users t...
vendor_debian·2012·CVSS 4.0
CVE-2012-1585 [MEDIUM] CVE-2012-1585: nova - OpenStack Compute (Nova) Essex before 2011.3 allows remote authenticated users t...
OpenStack Compute (Nova) Essex before 2011.3 allows remote authenticated users to cause a denial of service (Nova-API log file and disk consumption) via a long server name.
Scope: local
bookworm: resolved (fixed in 2012-1~rc3-1)
bullseye: resolved (fixed in 2012-1~rc3-1)
forky: resolved (fixed in 2012-1~rc3-1)
sid: resolved (fixed in 2012-1~rc3-1)
trixie: resolved (fixed in 2012-1~rc3-1)
GHSA
OpenStack Nova Long server names grow nova-api log files significantly
ghsa·2022-05-14
CVE-2012-1585 [MEDIUM] OpenStack Nova Long server names grow nova-api log files significantly
OpenStack Nova Long server names grow nova-api log files significantly
OpenStack Compute (Nova) Essex before 2011.3 allows remote authenticated users to cause a denial of service (Nova-API log file and disk consumption) via a long server name.
OSV
OpenStack Nova Long server names grow nova-api log files significantly
osv·2022-05-14
CVE-2012-1585 [MEDIUM] OpenStack Nova Long server names grow nova-api log files significantly
OpenStack Nova Long server names grow nova-api log files significantly
OpenStack Compute (Nova) Essex before 2011.3 allows remote authenticated users to cause a denial of service (Nova-API log file and disk consumption) via a long server name.
OSV
CVE-2012-1585: OpenStack Compute (Nova) Essex before 2011
osv·2012-08-17·CVSS 4.0
CVE-2012-1585 [MEDIUM] CVE-2012-1585: OpenStack Compute (Nova) Essex before 2011
OpenStack Compute (Nova) Essex before 2011.3 allows remote authenticated users to cause a denial of service (Nova-API log file and disk consumption) via a long server name.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-1585 openstack-nova: Long server names grow nova-api log files significantly [fedora-16]
bugzilla·2012-03-29·CVSS 4.0
CVE-2012-1585 [MEDIUM] CVE-2012-1585 openstack-nova: Long server names grow nova-api log files significantly [fedora-16]
CVE-2012-1585 openstack-nova: Long server names grow nova-api log files significantly [fedora-16]
please see the bug #808146 for more details on this vulnerability
Discussion:
openstack-nova-2011.3.1-7.fc16 has been submitted as an update for Fedora 16.
https://admin.fedoraproject.org/updates/openstack-nova-2011.3.1-7.fc16
---
Package openstack-nova-2011.3.1-7.fc16:
* should fix your issue,
* was pushed to the Fedora 16 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing openstack-nova-2011.3.1-7.fc16'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-2012-5026/openstack-nova-2011.3.1-7.fc16
then log in and leave karma (feedback).
---
Bugzilla
CVE-2012-1585 openstack-nova: Long server names grow nova-api log files significantly [epel-6]
bugzilla·2012-03-29·CVSS 4.0
CVE-2012-1585 [MEDIUM] CVE-2012-1585 openstack-nova: Long server names grow nova-api log files significantly [epel-6]
CVE-2012-1585 openstack-nova: Long server names grow nova-api log files significantly [epel-6]
please see the bug #808146 for more details on this vulnerability
Discussion:
openstack-nova-2011.3.1-7.el6 has been submitted as an update for Fedora EPEL 6.
https://admin.fedoraproject.org/updates/openstack-nova-2011.3.1-7.el6
---
openstack-nova-2011.3.1-8.el6 has been submitted as an update for Fedora EPEL 6.
https://admin.fedoraproject.org/updates/openstack-nova-2011.3.1-8.el6
---
Package openstack-nova-2011.3.1-8.el6:
* should fix your issue,
* was pushed to the Fedora EPEL 6 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=epel-testing openstack-nova-2011.3.1-8.el6'
as soon as you are able to.
Please go t
Bugzilla
CVE-2012-1585 openstack-nova: Long server names grow nova-api log files significantly [fedora-17]
bugzilla·2012-03-29·CVSS 4.0
CVE-2012-1585 [MEDIUM] CVE-2012-1585 openstack-nova: Long server names grow nova-api log files significantly [fedora-17]
CVE-2012-1585 openstack-nova: Long server names grow nova-api log files significantly [fedora-17]
please see the bug #808146 for more details on this vulnerability
Discussion:
openstack-nova-2012.1-0.10.rc1.fc17 has been submitted as an update for Fedora 17.
https://admin.fedoraproject.org/updates/openstack-nova-2012.1-0.10.rc1.fc17
---
Package openstack-nova-2012.1-0.10.rc1.fc17:
* should fix your issue,
* was pushed to the Fedora 17 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing openstack-nova-2012.1-0.10.rc1.fc17'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-2012-4889/openstack-nova-2012.1-0.10.rc1.fc17
then log in and leave
Bugzilla
CVE-2012-1585 openstack-nova: Long server names grow nova-api log files significantly
bugzilla·2012-03-29·CVSS 4.0
CVE-2012-1585 [MEDIUM] CVE-2012-1585 openstack-nova: Long server names grow nova-api log files significantly
CVE-2012-1585 openstack-nova: Long server names grow nova-api log files significantly
Dan Prince reported a vulnerability in OpenStack Compute (Nova) API servers. By PUTing or POSTing extremely long server names to the OpenStack API, any authenticated user may grow nova-api log files significantly, potentially resulting in disk space exhaustion and denial of service to the affected nova-api nodes. Only setups running the OpenStack API are affected.
Discussion:
References:
[1] http://osdir.com/ml/openstack-cloud-computing/2012-03/msg01133.html
[2] https://bugs.launchpad.net/nova/+bug/962515
[3] http://lwn.net/Alerts/491298/
2012-08-17
Published