CVE-2012-3447
published 2012-08-20CVE-2012-3447: virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom before Folsom-3 allows remote authenticated users to overwrite arbitrary files…
PriorityP426medium4.9CVSS 2.0
AVNACMAuSCNIPAP
EPSS
1.93%
77.8th percentile
virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom before Folsom-3 allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image that uses a symlink that is only readable by root. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3361.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2012.1.1-6 (bookworm) | nova 2012.1.1-6 (bookworm) |
| openstack | nova | — | — |
| openstack | nova | >= 0 < 2012.1.1-6 | 2012.1.1-6 |
| openstack | nova | >= 0 < 2012.1.1-6 | 2012.1.1-6 |
| openstack | nova | >= 0 < 2012.1.1-6 | 2012.1.1-6 |
| openstack | nova | >= 0 < 2012.1.1-6 | 2012.1.1-6 |
| openstack | nova | >= 0 < 12.0.0 | 12.0.0 |
CVSS provenance
nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:N/I:P/A:P
ghsa5.5MEDIUM
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Arbitrary file overwrite in OpenStack Nova
osv·2022-05-17·CVSS 5.5
CVE-2012-3447 [MEDIUM] Arbitrary file overwrite in OpenStack Nova
Arbitrary file overwrite in OpenStack Nova
`virt/disk/api.py` in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom before Folsom-3 allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image that uses a symlink that is only readable by root. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3361.
GHSA
Arbitrary file overwrite in OpenStack Nova
ghsa·2022-05-17·CVSS 5.5
CVE-2012-3447 [MEDIUM] CWE-863 Arbitrary file overwrite in OpenStack Nova
Arbitrary file overwrite in OpenStack Nova
`virt/disk/api.py` in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom before Folsom-3 allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image that uses a symlink that is only readable by root. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3361.
OSV
CVE-2012-3447: virt/disk/api
osv·2012-08-20·CVSS 5.5
CVE-2012-3447 [MEDIUM] CVE-2012-3447: virt/disk/api
virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom before Folsom-3 allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image that uses a symlink that is only readable by root. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3361.
Ubuntu
Nova vulnerability
vendor_ubuntu·2012-08-22·CVSS 5.5
CVE-2012-3447 [MEDIUM] Nova vulnerability
Title: Nova vulnerability
Summary: Nova could be made to overwrite or corrupt arbitrary files in the compute
host file system.
Padraig Brady discovered that the fix for CVE-2012-3361 was incomplete and
an authenticated user could still corrupt arbitrary files on the host
running Nova. A remote attacker could use this to cause a denial of service
or possibly gain privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2012-3447: nova - virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom...
vendor_debian·2012·CVSS 5.5
CVE-2012-3447 [MEDIUM] CVE-2012-3447: nova - virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom...
virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom before Folsom-3 allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image that uses a symlink that is only readable by root. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3361.
Scope: local
bookworm: resolved (fixed in 2012.1.1-6)
bullseye: resolved (fixed in 2012.1.1-6)
forky: resolved (fixed in 2012.1.1-6)
sid: resolved (fixed in 2012.1.1-6)
trixie: resolved (fixed in 2012.1.1-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3447 OpenStack-Nova: compute nodes disk image file corruption (incomplete fix for CVE-2012-3361) [fedora-all]
bugzilla·2012-08-08·CVSS 5.5
CVE-2012-3447 [MEDIUM] CVE-2012-3447 OpenStack-Nova: compute nodes disk image file corruption (incomplete fix for CVE-2012-3361) [fedora-all]
CVE-2012-3447 OpenStack-Nova: compute nodes disk image file corruption (incomplete fix for CVE-2012-3361) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fe
Bugzilla
CVE-2012-3447 OpenStack-Nova: compute nodes disk image file corruption (incomplete fix for CVE-2012-3361) [epel-6]
bugzilla·2012-08-08·CVSS 5.5
CVE-2012-3447 [MEDIUM] CVE-2012-3447 OpenStack-Nova: compute nodes disk image file corruption (incomplete fix for CVE-2012-3361) [epel-6]
CVE-2012-3447 OpenStack-Nova: compute nodes disk image file corruption (incomplete fix for CVE-2012-3361) [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedora
Bugzilla
CVE-2012-3447 OpenStack-Nova: compute nodes disk image file corruption, incomplete fix for CVE-2012-3361 (OSSA 2012-011)
bugzilla·2012-08-01·CVSS 5.5
CVE-2012-3447 [MEDIUM] CVE-2012-3447 OpenStack-Nova: compute nodes disk image file corruption, incomplete fix for CVE-2012-3361 (OSSA 2012-011)
CVE-2012-3447 OpenStack-Nova: compute nodes disk image file corruption, incomplete fix for CVE-2012-3361 (OSSA 2012-011)
Thierry Carrez reports:
Pádraig Brady from Red Hat discovered that the fix implemented for
CVE-2012-3361 (OSSA-2012-008) was not covering all attack scenarios. By
crafting a malicious image with root-readable-only symlinks and
requesting a server based on it, an authenticated user could still
corrupt arbitrary files (all setups affected) or inject arbitrary files
(Essex and later setups with OpenStack API enabled and a libvirt-based
hypervisor) on the host filesystem, potentially resulting in full
compromise of that compute node.
Discussion:
Created attachment 601803
Patch for CVE-2012-3447 for essex
---
Created attachment 601804
Patch for CVE-2012-3447 for folsom
http://www.openwall.com/lists/oss-security/2012/08/07/1http://www.securityfocus.com/bid/54869https://bugs.launchpad.net/nova/+bug/1031311https://bugzilla.redhat.com/show_bug.cgi?id=845106https://exchange.xforce.ibmcloud.com/vulnerabilities/77539https://github.com/openstack/nova/commit/ce4b2e27be45a85b310237615c47eb53f37bb5f3https://github.com/openstack/nova/commit/d9577ce9f266166a297488445b5b0c93c1ddb368https://review.openstack.org/#/c/10953/http://www.openwall.com/lists/oss-security/2012/08/07/1http://www.securityfocus.com/bid/54869https://bugs.launchpad.net/nova/+bug/1031311https://bugzilla.redhat.com/show_bug.cgi?id=845106https://exchange.xforce.ibmcloud.com/vulnerabilities/77539https://github.com/openstack/nova/commit/ce4b2e27be45a85b310237615c47eb53f37bb5f3https://github.com/openstack/nova/commit/d9577ce9f266166a297488445b5b0c93c1ddb368https://review.openstack.org/#/c/10953/
2012-08-20
Published