CVE-2012-3361: Medium severity Openstack Diablo vulnerability
virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image.
Other sources
virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3361?
CVE-2012-3361 has a medium severity rating due to its potential for remote authenticated users to exploit symlink vulnerabilities.
How do I fix CVE-2012-3361?
To fix CVE-2012-3361, upgrade your OpenStack Nova installation to version 12.0.0a0 or later.
What versions of OpenStack are affected by CVE-2012-3361?
CVE-2012-3361 affects OpenStack Compute (Nova) versions Folsom 2012.2, Essex 2012.1, and Diablo 2011.3.
What type of attack does CVE-2012-3361 allow?
CVE-2012-3361 allows a symlink attack that can overwrite arbitrary files on the system.
Who can exploit CVE-2012-3361?
CVE-2012-3361 can be exploited by remote authenticated users with sufficient permissions.