CVE-2012-5625
OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by…
Does this matter?
Lower severity and a low EPSS score (2.01%). Track it; it rarely justifies an emergency change on its own.
Description
OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by reading the memory of the previous logical volume (LV).
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 2.01% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- openstack/folsom · openstack/grizzly
- Source
- secalert@redhat.com
References
- http://osvdb.org/88419
- http://rhn.redhat.com/errata/RHSA-2013-0208.html
- http://www.openwall.com/lists/oss-security/2012/12/11/5
- http://www.securityfocus.com/bid/56904
- http://www.ubuntu.com/usn/USN-1663-1Patch
- https://bugs.launchpad.net/nova/+bug/1070539
- https://bugzilla.redhat.com/show_bug.cgi?id=884293
- https://github.com/openstack/nova/commit/9d2ea970422591f8cdc394001be9a2deca499a5fPatch
- https://github.com/openstack/nova/commit/a99a802e008eed18e39fc1d98170edc495cbd354Patch
- https://launchpad.net/nova/folsom/2012.2.2
- http://osvdb.org/88419
- http://rhn.redhat.com/errata/RHSA-2013-0208.html
- http://www.openwall.com/lists/oss-security/2012/12/11/5
- http://www.securityfocus.com/bid/56904
- http://www.ubuntu.com/usn/USN-1663-1Patch
- https://bugs.launchpad.net/nova/+bug/1070539
- https://bugzilla.redhat.com/show_bug.cgi?id=884293
- https://github.com/openstack/nova/commit/9d2ea970422591f8cdc394001be9a2deca499a5fPatch
- https://github.com/openstack/nova/commit/a99a802e008eed18e39fc1d98170edc495cbd354Patch
- https://launchpad.net/nova/folsom/2012.2.2
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.