Ustanovljen je i ispravljen sigurnosni nedostatak kod programskog paketa Nova. Udaljeni napadači su ga mogli iskoristiti za DoS napad.
Paket:
Operacijski sustavi:
Ubuntu Linux 12.04
Kritičnost:
3.5
Problem:
pogreška u programskoj funkciji
Iskorištavanje:
udaljeno
Posljedica:
uskraćivanje usluga (DoS)
Rješenje:
programska zakrpa proizvođača
CVE:
CVE-2012-3371
Izvorni ID preporuke:
USN-1501-1
Izvor:
Ubuntu
Problem:
Uočeno je da ukoliko program koristi filtere "DifferentHostFilter" ili "SameHostFilter" može neprestano pretraživati bazu podataka što u konačnici dovodi do pogreške.
Posljedica:
Zlonamjeran napadač može iskoristiti navedeni problem za napad uskraćivanjem usluga (eng. Denial of Service, DoS).
Rješenje:
Svim korisnicima se savjetuje korištenje programskih zakrpa proizvođača.
==========================================================================
Ubuntu Security Notice USN-1501-1
July 11, 2012
nova vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
Nova could be made to not respond if passed specially crafted input.
Software Description:
- nova: OpenStack Compute cloud infrastructure
Details:
Dan Prince discovered that the Nova scheduler, when using
DifferentHostFilter or SameHostFilter, would make repeated database
instance lookup calls based on passed scheduler hints. An authenticated
attacker could use this to cause a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
python-nova 2012.1+stable~20120612-3ee026e-0ubuntu1.2
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-1501-1
CVE-2012-3371
Package Information:
https://launchpad.net/ubuntu/+source/nova/2012.1+stable~20120612-3ee026e-0ubuntu1.2
Posljednje sigurnosne preporuke