LWN.net Logo

nova: group policy restriction

Package(s):nova CVE #(s):CVE-2012-2654
Created:June 7, 2012 Updated:June 26, 2012
Description:

From the Ubuntu advisory:

It was discovered that, when defining security groups in Nova using the EC2 or OS APIs, specifying the network protocol (e.g. 'TCP') in the incorrect case would cause the security group to not be applied correctly. An attacker could use this to bypass Nova security group restrictions.

Alerts:
Ubuntu USN-1466-1 2012-06-06
Ubuntu USN-1466-2 2012-06-12
Fedora FEDORA-2012-9425 2012-06-22
Fedora FEDORA-2012-9550 2012-06-26

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds