CVE-2013-2096: Low severity red hat openstack folsom vulnerability
OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) by creating an image with a large virtual size that does not contain a large amount of data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2096?
CVE-2013-2096 is classified as a denial of service vulnerability that can impact host file system stability.
How do I fix CVE-2013-2096?
To mitigate CVE-2013-2096, update to a later version of OpenStack that includes the fix for this vulnerability.
Which versions of OpenStack are affected by CVE-2013-2096?
CVE-2013-2096 affects OpenStack Compute (Nova) Folsom, Grizzly, and Havana.
What type of attack does CVE-2013-2096 facilitate?
CVE-2013-2096 allows local users to create a denial of service condition by filling the host file system with unverified virtual size QCOW2 images.
Can CVE-2013-2096 be exploited remotely?
CVE-2013-2096 requires local user access to exploit the denial of service vulnerability.