CVE-2013-1838
published 2013-03-22CVE-2013-1838: OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a quota for fixed IPs, which allows remote authenticated…
PriorityP417medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
2.74%
84.5th percentile
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a quota for fixed IPs, which allows remote authenticated users to cause a denial of service (resource exhaustion and failure to spawn new instances) via a large number of calls to the addFixedIp function.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | nova | < nova 2012.1.1-15 (bookworm) | nova 2012.1.1-15 (bookworm) |
| openstack | essex | — | — |
| openstack | folsom | — | — |
| openstack | grizzly | — | — |
| openstack | nova | >= 0 < 2012.1.1-15 | 2012.1.1-15 |
| openstack | nova | >= 0 < 2012.1.1-15 | 2012.1.1-15 |
| openstack | nova | >= 0 < 2012.1.1-15 | 2012.1.1-15 |
| openstack | nova | >= 0 < 2012.1.1-15 | 2012.1.1-15 |
| openstack | nova | >= 0 < 12.0.0a0 | 12.0.0a0 |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.0MEDIUM
vendor_ubuntu6.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
OpenStack Compute (Nova) Denial of service via a large number of calls to the addFixedIp function
osv·2022-05-17
CVE-2013-1838 [HIGH] OpenStack Compute (Nova) Denial of service via a large number of calls to the addFixedIp function
OpenStack Compute (Nova) Denial of service via a large number of calls to the addFixedIp function
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a quota for fixed IPs, which allows remote authenticated users to cause a denial of service (resource exhaustion and failure to spawn new instances) via a large number of calls to the addFixedIp function.
GHSA
OpenStack Compute (Nova) Denial of service via a large number of calls to the addFixedIp function
ghsa·2022-05-17
CVE-2013-1838 [HIGH] CWE-770 OpenStack Compute (Nova) Denial of service via a large number of calls to the addFixedIp function
OpenStack Compute (Nova) Denial of service via a large number of calls to the addFixedIp function
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a quota for fixed IPs, which allows remote authenticated users to cause a denial of service (resource exhaustion and failure to spawn new instances) via a large number of calls to the addFixedIp function.
OSV
CVE-2013-1838: OpenStack Compute (Nova) Grizzly, Folsom (2012
osv·2013-03-22·CVSS 4.0
CVE-2013-1838 [MEDIUM] CVE-2013-1838: OpenStack Compute (Nova) Grizzly, Folsom (2012
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a quota for fixed IPs, which allows remote authenticated users to cause a denial of service (resource exhaustion and failure to spawn new instances) via a large number of calls to the addFixedIp function.
Ubuntu
OpenStack Nova vulnerabilities
vendor_ubuntu·2013-03-20·CVSS 6.0
CVE-2013-0335 [MEDIUM] OpenStack Nova vulnerabilities
Title: OpenStack Nova vulnerabilities
Summary: Two security issues were fixed in Nova.
Loganathan Parthipan discovered that Nova did not properly validate VNC
tokens after an instance was deleted. An authenticated attacker could
exploit this to access other virtual machines under certain circumstances.
This issue did not affect Ubuntu 11.10. (CVE-2013-0335)
Vish Ishaya discovered that Nova did not always enforce quotas on fixed
IPs. An authenticated attacker could exploit this to cause a denial of
service via resource consumption. Nova will now enforce a quota limit of
10 fixed IPs per instance, which is configurable via 'quota_fixed_ips'
in /etc/nova/nova.conf. (CVE-2013-1838)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
Nova: DoS by allocating all Fixed IPs
vendor_redhat·2013-03-14·CVSS 4.0
CVE-2013-1838 [MEDIUM] Nova: DoS by allocating all Fixed IPs
Nova: DoS by allocating all Fixed IPs
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a quota for fixed IPs, which allows remote authenticated users to cause a denial of service (resource exhaustion and failure to spawn new instances) via a large number of calls to the addFixedIp function.
Debian
CVE-2013-1838: nova - OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not p...
vendor_debian·2013·CVSS 4.0
CVE-2013-1838 [MEDIUM] CVE-2013-1838: nova - OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not p...
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a quota for fixed IPs, which allows remote authenticated users to cause a denial of service (resource exhaustion and failure to spawn new instances) via a large number of calls to the addFixedIp function.
Scope: local
bookworm: resolved (fixed in 2012.1.1-15)
bullseye: resolved (fixed in 2012.1.1-15)
forky: resolved (fixed in 2012.1.1-15)
sid: resolved (fixed in 2012.1.1-15)
trixie: resolved (fixed in 2012.1.1-15)
No detection rules found.
No public exploits indexed.
http://osvdb.org/91303http://rhn.redhat.com/errata/RHSA-2013-0709.htmlhttp://secunia.com/advisories/52580http://secunia.com/advisories/52728http://ubuntu.com/usn/usn-1771-1http://www.openwall.com/lists/oss-security/2013/03/14/18http://www.securityfocus.com/bid/58492https://bugs.launchpad.net/nova/+bug/1125468https://bugzilla.redhat.com/show_bug.cgi?id=919648https://exchange.xforce.ibmcloud.com/vulnerabilities/82877https://lists.launchpad.net/openstack/msg21892.htmlhttps://review.openstack.org/#/c/24451/https://review.openstack.org/#/c/24452/https://review.openstack.org/#/c/24453/http://osvdb.org/91303http://rhn.redhat.com/errata/RHSA-2013-0709.htmlhttp://secunia.com/advisories/52580http://secunia.com/advisories/52728http://ubuntu.com/usn/usn-1771-1http://www.openwall.com/lists/oss-security/2013/03/14/18http://www.securityfocus.com/bid/58492https://bugs.launchpad.net/nova/+bug/1125468https://bugzilla.redhat.com/show_bug.cgi?id=919648https://exchange.xforce.ibmcloud.com/vulnerabilities/82877https://lists.launchpad.net/openstack/msg21892.htmlhttps://review.openstack.org/#/c/24451/https://review.openstack.org/#/c/24452/https://review.openstack.org/#/c/24453/
2013-03-22
Published