Release date: 2012-03-30
Updated on:
Affected Systems:
Launchpad Jesse Andrews OpenStack Compute (OVA) 2011.3
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52831
Cve id: CVE-2012-1585
OpenStack Compute (Nova) is a cloud computing constructor written in Python and is part of the laaS system.
OpenStack Compute (Nova) has a denial of service vulnerability in the implementation of glance. client update_image in. Remote attackers can exploit this vulnerability to cause application crash.
<* Source: Dan Prince
Link: https://bugs.launchpad.net/glance/+bug/845788
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Launchpad
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://launchpad.net/nova