Kod programskog paketa openstack-nova uočeno je više sigurnosnih propusta koje udaljeni napadač može iskoristiti za napad uskraćivanjem usluga (DoS) te zaobilaženje postavljenih ograničenja.
Sigurnosni propusti se javljaju zbog pogrešne implementacije "EC2" i "OS" sučelja, pogrešnog postavljanja pravila sigurnosnih grupa te neodgovarajuće provjere "project_id" parametra u sučelju "OpenStack".
Posljedica:
Udaljeni napadač spomenute ranjivosti može iskoristiti za DoS (eng. Denial of Service) napad te zaobilaženje postavljenih ograničenja.
Rješenje:
Rješenje problema sigurnosti je nadogradnja paketa na novije inačice.
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-9550
2012-06-16 23:34:46
--------------------------------------------------------------------------------
Name : openstack-nova
Product : Fedora 17
Version : 2012.1
Release : 10.fc17
URL : http://openstack.org/projects/compute/
Summary : OpenStack Compute (nova)
Description :
OpenStack Compute (codename Nova) is open source software designed to
provision and manage large networks of virtual machines, creating a
redundant and scalable cloud computing platform. It gives you the
software, control panels, and APIs required to orchestrate a cloud,
including running instances, managing networks, and controlling access
through users and projects. OpenStack Compute strives to be both
hardware and hypervisor agnostic, currently supporting a variety of
standard hardware configurations and seven major hypervisors.
--------------------------------------------------------------------------------
Update Information:
bug fixes and performance improvements from stable essex
- fix an exception caused by the fix for CVE-2012-2654
- fix the encoding of the dns_domains table (requires a db sync)
- fix a crash due to a nova services startup race (#825051)
- Fix for protocol case handling CVE-2012-2654
--------------------------------------------------------------------------------
ChangeLog:
* Mon Jun 11 2012 PÄ
Posljednje sigurnosne preporuke