LWN.net Logo

nova: access controls bypass

Package(s):nova CVE #(s):CVE-2013-0208
Created:January 30, 2013 Updated:February 10, 2013
Description: From the Ubuntu advisory:

Phil Day discovered that nova-volume did not validate access to volumes. An authenticated attacker could exploit this to bypass intended access controls and boot from arbitrary volumes.

Alerts:
Ubuntu USN-1709-1 2013-01-29
Red Hat RHSA-2013:0208-01 2013-01-30
Fedora FEDORA-2013-1816 2013-02-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds