CVE-2013-4463
published 2014-02-06CVE-2013-4463: OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly verify the virtual size of a QCOW2 image, which allows local users to cause a denial of…
PriorityP47low2.1CVSS 2.0
AVLACLAuNCNINAP
EPSS
0.37%
29.4th percentile
OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) via a compressed QCOW2 image. NOTE: this issue is due to an incomplete fix for CVE-2013-2096.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2013.2-3 (bookworm) | nova 2013.2-3 (bookworm) |
| openstack | nova | >= 0 < 2013.2-3 | 2013.2-3 |
| openstack | nova | >= 0 < 2013.2-3 | 2013.2-3 |
| openstack | nova | >= 0 < 2013.2-3 | 2013.2-3 |
| openstack | nova | >= 0 < 2013.2-3 | 2013.2-3 |
| openstack | nova | >= 0 < 12.0.0a0 | 12.0.0a0 |
| openstack | nova | >= 0 < 1:2014.1-0ubuntu1.2 | 1:2014.1-0ubuntu1.2 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
ghsa2.1LOW
osv5.0MEDIUM
vendor_ubuntu5.0MEDIUM
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
OpenStack Nova denial of service through compressed disk images
osv·2022-05-17·CVSS 2.1
CVE-2013-4463 [LOW] OpenStack Nova denial of service through compressed disk images
OpenStack Nova denial of service through compressed disk images
OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) via a compressed QCOW2 image. NOTE: this issue is due to an incomplete fix for CVE-2013-2096.
GHSA
OpenStack Nova denial of service through compressed disk images
ghsa·2022-05-17·CVSS 2.1
CVE-2013-4463 [LOW] OpenStack Nova denial of service through compressed disk images
OpenStack Nova denial of service through compressed disk images
OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) via a compressed QCOW2 image. NOTE: this issue is due to an incomplete fix for CVE-2013-2096.
OSV
nova vulnerabilities
osv·2014-06-17·CVSS 5.0
CVE-2013-1068 [MEDIUM] nova vulnerabilities
nova vulnerabilities
Darragh O'Reilly discovered that the Ubuntu packaging for OpenStack Nova
did not properly set up its sudo configuration. If a different flaw was
found in OpenStack Nova, this vulnerability could be used to escalate
privileges. This issue only affected Ubuntu 13.10 and Ubuntu 14.04 LTS.
(CVE-2013-1068)
Bernhard M. Wiedemann and Pedraig Brady discovered that OpenStack Nova did
not properly verify the virtual size of a QCOW2 images. A remote
authenticated attacker could exploit this to create a denial of service via
disk consumption. This issue did not affect Ubuntu 14.04 LTS.
(CVE-2013-4463, CVE-2013-4469)
JuanFra Rodriguez Cardoso discovered that OpenStack Nova did not enforce
SSL connections when Nova was configured to use QPid and qpid_protocol is
set to 'ssl'. If
OSV
CVE-2013-4463: OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly verify the virtual size of a QCOW2 image, which allows local users to cause a d
osv·2014-02-06·CVSS 2.1
CVE-2013-4463 [LOW] CVE-2013-4463: OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly verify the virtual size of a QCOW2 image, which allows local users to cause a d
OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) via a compressed QCOW2 image. NOTE: this issue is due to an incomplete fix for CVE-2013-2096.
Ubuntu
OpenStack Nova vulnerabilities
vendor_ubuntu·2014-06-17·CVSS 5.0
CVE-2013-1068 [MEDIUM] OpenStack Nova vulnerabilities
Title: OpenStack Nova vulnerabilities
Summary: Several security issues were fixed in OpenStack Nova.
Darragh O'Reilly discovered that the Ubuntu packaging for OpenStack Nova
did not properly set up its sudo configuration. If a different flaw was
found in OpenStack Nova, this vulnerability could be used to escalate
privileges. This issue only affected Ubuntu 13.10 and Ubuntu 14.04 LTS.
(CVE-2013-1068)
Bernhard M. Wiedemann and Pedraig Brady discovered that OpenStack Nova did
not properly verify the virtual size of a QCOW2 images. A remote
authenticated attacker could exploit this to create a denial of service via
disk consumption. This issue did not affect Ubuntu 14.04 LTS.
(CVE-2013-4463, CVE-2013-4469)
JuanFra Rodriguez Cardoso discovered that OpenStack Nova did not enforce
SSL connec
Red Hat
Nova: Compressed disk image DoS
vendor_redhat·2013-10-31·CVSS 2.1
CVE-2013-4463 [LOW] Nova: Compressed disk image DoS
Nova: Compressed disk image DoS
OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) via a compressed QCOW2 image. NOTE: this issue is due to an incomplete fix for CVE-2013-2096.
Statement: The Red Hat Security Response Team has rated this issue as having moderate security impact. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: openstack-nova (Red Hat OpenStack Platform 4) - Affected
Debian
CVE-2013-4463: nova - OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly verify th...
vendor_debian·2013·CVSS 2.1
CVE-2013-4463 [LOW] CVE-2013-4463: nova - OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly verify th...
OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) via a compressed QCOW2 image. NOTE: this issue is due to an incomplete fix for CVE-2013-2096.
Scope: local
bookworm: resolved (fixed in 2013.2-3)
bullseye: resolved (fixed in 2013.2-3)
forky: resolved (fixed in 2013.2-3)
sid: resolved (fixed in 2013.2-3)
trixie: resolved (fixed in 2013.2-3)
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2014-0112.htmlhttp://www.openwall.com/lists/oss-security/2013/10/31/3http://www.ubuntu.com/usn/USN-2247-1https://bugs.launchpad.net/nova/+bug/1206081http://rhn.redhat.com/errata/RHSA-2014-0112.htmlhttp://www.openwall.com/lists/oss-security/2013/10/31/3http://www.ubuntu.com/usn/USN-2247-1https://bugs.launchpad.net/nova/+bug/1206081
2014-02-06
Published