CVE-2012-5625

OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by reading the memory of the previous logical volume (LV).
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openstack:folsom:2012.2:*:*:*:*:*:*:*
cpe:2.3:a:openstack:grizzly:-:*:*:*:*:*:*:*

History

21 Nov 2024, 01:44

Type Values Removed Values Added
References () http://osvdb.org/88419 - () http://osvdb.org/88419 -
References () http://rhn.redhat.com/errata/RHSA-2013-0208.html - () http://rhn.redhat.com/errata/RHSA-2013-0208.html -
References () http://www.openwall.com/lists/oss-security/2012/12/11/5 - () http://www.openwall.com/lists/oss-security/2012/12/11/5 -
References () http://www.securityfocus.com/bid/56904 - () http://www.securityfocus.com/bid/56904 -
References () http://www.ubuntu.com/usn/USN-1663-1 - Patch () http://www.ubuntu.com/usn/USN-1663-1 - Patch
References () https://bugs.launchpad.net/nova/+bug/1070539 - () https://bugs.launchpad.net/nova/+bug/1070539 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=884293 - () https://bugzilla.redhat.com/show_bug.cgi?id=884293 -
References () https://github.com/openstack/nova/commit/9d2ea970422591f8cdc394001be9a2deca499a5f - Patch () https://github.com/openstack/nova/commit/9d2ea970422591f8cdc394001be9a2deca499a5f - Patch
References () https://github.com/openstack/nova/commit/a99a802e008eed18e39fc1d98170edc495cbd354 - Patch () https://github.com/openstack/nova/commit/a99a802e008eed18e39fc1d98170edc495cbd354 - Patch
References () https://launchpad.net/nova/folsom/2012.2.2 - () https://launchpad.net/nova/folsom/2012.2.2 -

Information

Published : 2012-12-26 22:55

Updated : 2024-11-21 01:44


NVD link : CVE-2012-5625

Mitre link : CVE-2012-5625

CVE.ORG link : CVE-2012-5625


JSON object : View

Products Affected

openstack

  • grizzly
  • folsom
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor