CVE-2012-1585: Medium severity Openstack Nova vulnerability
Published Aug 17, 2012
·Updated
OpenStack Compute (Nova) Essex before 2011.3 allows remote authenticated users to cause a denial of service (Nova-API log file and disk consumption) via a long server name.
Affected Software
2 affected componentsFixes available
pip/nova<12.0.0a0
12.0.0a0
Openstack Nova>=2011.1<2011.3
Event History
Aug 17, 2012
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
May 14, 2022
Advisory Published
via GitHub·01:59 AM
Frequently Asked Questions
1
What is the severity of CVE-2012-1585?
CVE-2012-1585 is considered to have a moderate severity level due to its potential for denial of service.
2
How do I fix CVE-2012-1585?
To fix CVE-2012-1585, upgrade OpenStack Nova to version 12.0.0a0 or higher.
3
Who is affected by CVE-2012-1585?
CVE-2012-1585 affects remote authenticated users of OpenStack Compute (Nova) Essex before version 2011.3.
4
What type of attack is CVE-2012-1585?
CVE-2012-1585 can be exploited through a denial of service attack via excessively long server names.
5
What are the implications of CVE-2012-1585?
The implications of CVE-2012-1585 include potential disk consumption and log file flooding, which can disrupt service availability.