cbcvebase.
CVE-2012-3447
published 2012-08-20

CVE-2012-3447: virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom before Folsom-3 allows remote authenticated users to overwrite arbitrary files…

medium4.9CVSS 3.1
AVNACMAuSCNIPAP
virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom before Folsom-3 allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image that uses a symlink that is only readable by root. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3361.

Affected

7 ranges
VendorProductVersion rangeFixed in
debiannova< nova 2012.1.1-6 (bookworm)nova 2012.1.1-6 (bookworm)
openstacknova
openstacknova>= 0 < 2012.1.1-62012.1.1-6
openstacknova>= 0 < 2012.1.1-62012.1.1-6
openstacknova>= 0 < 2012.1.1-62012.1.1-6
openstacknova>= 0 < 2012.1.1-62012.1.1-6
openstacknova>= 0 < 12.0.012.0.0

CVSS provenance

nvd4.9MEDIUMAV:N/AC:M/Au:S/C:N/I:P/A:P
ghsa5.5MEDIUM
osv5.5MEDIUM