cbcvebase.
CVE-2013-6437
published 2014-03-06

CVE-2013-6437: The libvirt driver in OpenStack Compute (Nova) before 2013.2.2 and icehouse before icehouse-2 allows remote authenticated users to cause a denial of service…

medium4CVSS 3.1
AVNACLAuSCNINAP
The libvirt driver in OpenStack Compute (Nova) before 2013.2.2 and icehouse before icehouse-2 allows remote authenticated users to cause a denial of service (disk consumption) by creating and deleting instances with unique os_type settings, which triggers the creation of a new ephemeral disk backing file.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiannova< nova 2013.2.2 (bookworm)nova 2013.2.2 (bookworm)
openstacknova
openstacknova>= 0 < 2013.2.22013.2.2
openstacknova>= 0 < 2013.2.22013.2.2
openstacknova>= 0 < 2013.2.22013.2.2
openstacknova>= 0 < 2013.2.22013.2.2
openstacknova>= 0 < 12.0.0a012.0.0a0
openstacknova>= 2013.1 < 2013.1.52013.1.5
openstacknova>= 2013.2 < 2013.2.22013.2.2

CVSS provenance

nvd4.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.0MEDIUM