First published: Mon Oct 06 2014(Updated: )
The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2573.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Nova-LXD | >=2013.2<=2013.2.4 | |
OpenStack Nova-LXD | >=2014.1<2014.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3608 is classified as a medium-severity vulnerability.
To fix CVE-2014-3608, upgrade OpenStack Nova to version 2014.1.3 or later.
CVE-2014-3608 affects users running OpenStack Nova versions prior to 2014.1.3.
CVE-2014-3608 exploits a vulnerability in the VMWare driver allowing quota limit bypass.
The impact of CVE-2014-3608 can lead to denial of service due to resource consumption.