CVE-2013-6437: Medium severity Openstack Nova vulnerability
The libvirt driver in OpenStack Compute (Nova) before 2013.2.2 and icehouse before icehouse-2 allows remote authenticated users to cause a denial of service (disk consumption) by creating and deleting instances with unique ostype settings, which triggers the creation of a new ephemeral disk backing file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/novato a version that resolves this vulnerability.Fixed in 12.0.0a0
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6437?
CVE-2013-6437 is classified as a medium severity vulnerability due to its potential for causing denial of service by consuming disk space.
How do I fix CVE-2013-6437?
To mitigate CVE-2013-6437, upgrade OpenStack Nova to version 2013.2.2 or later.
Who is affected by CVE-2013-6437?
CVE-2013-6437 affects versions of OpenStack Nova prior to 2013.2.2 and specific milestone releases.
What type of attack does CVE-2013-6437 facilitate?
CVE-2013-6437 facilitates a denial of service attack through excessive disk consumption from instance creation and deletion.
What actions can authenticated users take that trigger CVE-2013-6437?
Authenticated users can cause CVE-2013-6437 by creating and deleting instances with unique os_type settings.