CVE-2011-3147: qcow format could expose host filesystem information
Published Apr 22, 2019
·Updated
Versions of nova before 2012.1 could expose hypervisor host files to a guest operating system when processing a maliciously constructed qcow filesystem.
Affected Software
2 affected componentsFixes available
pip/nova<12.0.0a0
12.0.0a0
Openstack Nova>=2010.1<2012.1
Remediation
Event History
Apr 22, 2019
CVE Published
via MITRE·03:35 PM
Data Sourced
via MITRE·03:35 PM
DescriptionSeverity
Apr 22, 2022
Advisory Published
via GitHub·12:24 AM
Frequently Asked Questions
1
What is the severity of CVE-2011-3147?
The severity of CVE-2011-3147 is high with a severity value of 8.6.
2
What is the affected software version of CVE-2011-3147?
Versions of OpenStack Nova before 2012.1 are affected by CVE-2011-3147.
3
How does CVE-2011-3147 expose hypervisor host files to a guest operating system?
CVE-2011-3147 can expose hypervisor host files to a guest operating system when processing a maliciously constructed qcow filesystem.
4
How can I fix CVE-2011-3147?
To fix CVE-2011-3147, it is recommended to update to the version 2012.1 or newer of OpenStack Nova.
5
Is there any reference available for CVE-2011-3147?
Yes, you can find more information about CVE-2011-3147 at http://bazaar.launchpad.net/~hudson-openstack/nova/trunk/revision/1604