CVE-2012-3361
published 2012-07-22CVE-2012-3361: virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbitrary…
PriorityP428medium5.5CVSS 2.0
AVNACLAuSCNIPAP
EPSS
2.58%
83.5th percentile
virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2012.1.1-6 (bookworm) | nova 2012.1.1-6 (bookworm) |
| debian | nova | < nova 2012.1.1-2 (bookworm) | nova 2012.1.1-2 (bookworm) |
| openstack | diablo | — | — |
| openstack | essex | — | — |
| openstack | folsom | — | — |
| openstack | nova | — | — |
| openstack | nova | >= 0 < 2012.1.1-2 | 2012.1.1-2 |
| openstack | nova | >= 0 < 2012.1.1-6 | 2012.1.1-6 |
| openstack | nova | >= 0 < 2012.1.1-2 | 2012.1.1-2 |
| openstack | nova | >= 0 < 2012.1.1-6 | 2012.1.1-6 |
| openstack | nova | >= 0 < 2012.1.1-2 | 2012.1.1-2 |
| openstack | nova | >= 0 < 2012.1.1-6 | 2012.1.1-6 |
| openstack | nova | >= 0 < 2012.1.1-2 | 2012.1.1-2 |
| openstack | nova | >= 0 < 2012.1.1-6 | 2012.1.1-6 |
| openstack | nova | >= 0 < 12.0.0 | 12.0.0 |
| openstack | nova | >= 0 < 12.0.0a0 | 12.0.0a0 |
CVSS provenance
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
ghsa5.5MEDIUM
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Arbitrary file overwrite in OpenStack Nova
osv·2022-05-17·CVSS 5.5
CVE-2012-3447 [MEDIUM] Arbitrary file overwrite in OpenStack Nova
Arbitrary file overwrite in OpenStack Nova
`virt/disk/api.py` in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom before Folsom-3 allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image that uses a symlink that is only readable by root. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3361.
GHSA
OpenStack Nova Arbitrary file injection/corruption through directory traversal issues
ghsa·2022-05-17
CVE-2012-3361 [MEDIUM] OpenStack Nova Arbitrary file injection/corruption through directory traversal issues
OpenStack Nova Arbitrary file injection/corruption through directory traversal issues
`virt/disk/api.py` in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image.
GHSA
Arbitrary file overwrite in OpenStack Nova
ghsa·2022-05-17·CVSS 5.5
CVE-2012-3447 [MEDIUM] CWE-863 Arbitrary file overwrite in OpenStack Nova
Arbitrary file overwrite in OpenStack Nova
`virt/disk/api.py` in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom before Folsom-3 allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image that uses a symlink that is only readable by root. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3361.
OSV
OpenStack Nova Arbitrary file injection/corruption through directory traversal issues
osv·2022-05-17
CVE-2012-3361 [MEDIUM] OpenStack Nova Arbitrary file injection/corruption through directory traversal issues
OpenStack Nova Arbitrary file injection/corruption through directory traversal issues
`virt/disk/api.py` in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image.
OSV
CVE-2012-3447: virt/disk/api
osv·2012-08-20·CVSS 5.5
CVE-2012-3447 [MEDIUM] CVE-2012-3447: virt/disk/api
virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom before Folsom-3 allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image that uses a symlink that is only readable by root. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3361.
OSV
CVE-2012-3361: virt/disk/api
osv·2012-07-22·CVSS 5.5
CVE-2012-3361 [MEDIUM] CVE-2012-3361: virt/disk/api
virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image.
Ubuntu
Nova vulnerability
vendor_ubuntu·2012-08-22·CVSS 5.5
CVE-2012-3447 [MEDIUM] Nova vulnerability
Title: Nova vulnerability
Summary: Nova could be made to overwrite or corrupt arbitrary files in the compute
host file system.
Padraig Brady discovered that the fix for CVE-2012-3361 was incomplete and
an authenticated user could still corrupt arbitrary files on the host
running Nova. A remote attacker could use this to cause a denial of service
or possibly gain privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Nova vulnerabilities
vendor_ubuntu·2012-07-03·CVSS 5.5
CVE-2012-3360 [MEDIUM] Nova vulnerabilities
Title: Nova vulnerabilities
Summary: Nova could be made to overwrite or corrupt arbitrary files in the
compute host file system.
Matthias Weckbecker discovered that, when using the OpenStack API to
setup libvirt-based hypervisors, an authenticated user could inject
files in arbitrary locations on the file system of the host running
Nova. A remote attacker could use this to gain root privileges. This
issue only affects Ubuntu 12.04 LTS. (CVE-2012-3360)
Pádraig Brady discovered that an authenticated user could corrupt
arbitrary files of the host running Nova. A remote attacker could
use this to cause a denial of service or possibly gain privileges.
(CVE-2012-3361)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2012-3447: nova - virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom...
vendor_debian·2012·CVSS 5.5
CVE-2012-3447 [MEDIUM] CVE-2012-3447: nova - virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom...
virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom before Folsom-3 allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image that uses a symlink that is only readable by root. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3361.
Scope: local
bookworm: resolved (fixed in 2012.1.1-6)
bullseye: resolved (fixed in 2012.1.1-6)
forky: resolved (fixed in 2012.1.1-6)
sid: resolved (fixed in 2012.1.1-6)
trixie: resolved (fixed in 2012.1.1-6)
Debian
CVE-2012-3361: nova - virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), an...
vendor_debian·2012·CVSS 5.5
CVE-2012-3361 [MEDIUM] CVE-2012-3361: nova - virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), an...
virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image.
Scope: local
bookworm: resolved (fixed in 2012.1.1-2)
bullseye: resolved (fixed in 2012.1.1-2)
forky: resolved (fixed in 2012.1.1-2)
sid: resolved (fixed in 2012.1.1-2)
trixie: resolved (fixed in 2012.1.1-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3447 OpenStack-Nova: compute nodes disk image file corruption (incomplete fix for CVE-2012-3361) [fedora-all]
bugzilla·2012-08-08·CVSS 5.5
CVE-2012-3447 [MEDIUM] CVE-2012-3447 OpenStack-Nova: compute nodes disk image file corruption (incomplete fix for CVE-2012-3361) [fedora-all]
CVE-2012-3447 OpenStack-Nova: compute nodes disk image file corruption (incomplete fix for CVE-2012-3361) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fe
Bugzilla
CVE-2012-3447 OpenStack-Nova: compute nodes disk image file corruption (incomplete fix for CVE-2012-3361) [epel-6]
bugzilla·2012-08-08·CVSS 5.5
CVE-2012-3447 [MEDIUM] CVE-2012-3447 OpenStack-Nova: compute nodes disk image file corruption (incomplete fix for CVE-2012-3361) [epel-6]
CVE-2012-3447 OpenStack-Nova: compute nodes disk image file corruption (incomplete fix for CVE-2012-3361) [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedora
Bugzilla
CVE-2012-3447 OpenStack-Nova: compute nodes disk image file corruption, incomplete fix for CVE-2012-3361 (OSSA 2012-011)
bugzilla·2012-08-01·CVSS 5.5
CVE-2012-3447 [MEDIUM] CVE-2012-3447 OpenStack-Nova: compute nodes disk image file corruption, incomplete fix for CVE-2012-3361 (OSSA 2012-011)
CVE-2012-3447 OpenStack-Nova: compute nodes disk image file corruption, incomplete fix for CVE-2012-3361 (OSSA 2012-011)
Thierry Carrez reports:
Pádraig Brady from Red Hat discovered that the fix implemented for
CVE-2012-3361 (OSSA-2012-008) was not covering all attack scenarios. By
crafting a malicious image with root-readable-only symlinks and
requesting a server based on it, an authenticated user could still
corrupt arbitrary files (all setups affected) or inject arbitrary files
(Essex and later setups with OpenStack API enabled and a libvirt-based
hypervisor) on the host filesystem, potentially resulting in full
compromise of that compute node.
Discussion:
Created attachment 601803
Patch for CVE-2012-3447 for essex
---
Created attachment 601804
Patch for CVE-2012-3447 for folsom
Bugzilla
CVE-2012-3361 OpenStack-Nova: compute nodes disk image file corruption [epel-6]
bugzilla·2012-07-28·CVSS 5.5
CVE-2012-3361 [MEDIUM] CVE-2012-3361 OpenStack-Nova: compute nodes disk image file corruption [epel-6]
CVE-2012-3361 OpenStack-Nova: compute nodes disk image file corruption [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=secu
Bugzilla
CVE-2012-3361 OpenStack-Nova: compute nodes disk image file corruption [fedora-all]
bugzilla·2012-07-28·CVSS 5.5
CVE-2012-3361 [MEDIUM] CVE-2012-3361 OpenStack-Nova: compute nodes disk image file corruption [fedora-all]
CVE-2012-3361 OpenStack-Nova: compute nodes disk image file corruption [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=
Bugzilla
CVE-2012-3361 OpenStack-Nova: compute nodes disk image file corruption
bugzilla·2012-06-28·CVSS 5.5
CVE-2012-3361 [MEDIUM] CVE-2012-3361 OpenStack-Nova: compute nodes disk image file corruption
CVE-2012-3361 OpenStack-Nova: compute nodes disk image file corruption
Thierry Carrez reports:
Pádraig Brady (Red Hat) Products: Nova Affects: All versions
Upon further inspection of the code, Pádraig Brady from Red Hat
found an additional vulnerability. By crafting a malicious image
and requesting an instance based on it, a remote authenticated user
may corrupt arbitrary files on the host filesystem, potentially
resulting in a denial of service. This affects all setups.
Discussion:
This is public now www.openwall.com/lists/oss-security/2012/07/03/2 filing trackers
---
References:
https://bugs.launchpad.net/nova/+bug/1015531
http://www.openwall.com/lists/oss-security/2012/07/03/2
Fixes:
Folsom:
https://github.com/openstack/nova/commit/2427d4a99bed35baefd8f17ba422cb7aae8dcca7
Esse
http://lists.fedoraproject.org/pipermail/package-announce/2012-July/083969.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-July/083984.htmlhttp://secunia.com/advisories/49763http://secunia.com/advisories/49802http://www.securityfocus.com/bid/54278http://www.ubuntu.com/usn/USN-1497-1https://bugs.launchpad.net/nova/+bug/1015531https://github.com/openstack/nova/commit/2427d4a99bed35baefd8f17ba422cb7aae8dcca7https://github.com/openstack/nova/commit/b0feaffdb2b1c51182b8dce41b367f3449af5dd9https://lists.launchpad.net/openstack/msg14089.htmlhttps://review.openstack.org/#/c/9268/http://lists.fedoraproject.org/pipermail/package-announce/2012-July/083969.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-July/083984.htmlhttp://secunia.com/advisories/49763http://secunia.com/advisories/49802http://www.securityfocus.com/bid/54278http://www.ubuntu.com/usn/USN-1497-1https://bugs.launchpad.net/nova/+bug/1015531https://github.com/openstack/nova/commit/2427d4a99bed35baefd8f17ba422cb7aae8dcca7https://github.com/openstack/nova/commit/b0feaffdb2b1c51182b8dce41b367f3449af5dd9https://lists.launchpad.net/openstack/msg14089.htmlhttps://review.openstack.org/#/c/9268/
2012-07-22
Published