CVE-2014-8750

Race condition in the VMware driver in OpenStack Compute (Nova) before 2014.1.4 and 2014.2 before 2014.2rc1 allows remote authenticated users to access unintended consoles by spawning an instance that triggers the same VNC port to be allocated to two different instances.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:nova:2014.2:milestone1:*:*:*:*:*:*
cpe:2.3:a:openstack:nova:2014.2:milestone2:*:*:*:*:*:*
cpe:2.3:a:openstack:nova:2014.2:milestone3:*:*:*:*:*:*

History

21 Nov 2024, 02:19

Type Values Removed Values Added
References () http://lists.openstack.org/pipermail/openstack-announce/2014-October/000293.html - Vendor Advisory () http://lists.openstack.org/pipermail/openstack-announce/2014-October/000293.html - Vendor Advisory
References () http://rhn.redhat.com/errata/RHSA-2014-1689.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2014-1689.html - Third Party Advisory
References () http://rhn.redhat.com/errata/RHSA-2014-1781.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2014-1781.html - Third Party Advisory
References () http://rhn.redhat.com/errata/RHSA-2014-1782.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2014-1782.html - Third Party Advisory
References () http://secunia.com/advisories/60227 - Third Party Advisory () http://secunia.com/advisories/60227 - Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2014/10/14/9 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2014/10/14/9 - Mailing List, Third Party Advisory
References () http://www.securityfocus.com/bid/70182 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/70182 - Third Party Advisory, VDB Entry
References () https://bugs.launchpad.net/nova/+bug/1357372 - Third Party Advisory () https://bugs.launchpad.net/nova/+bug/1357372 - Third Party Advisory

Information

Published : 2014-10-15 14:55

Updated : 2024-11-21 02:19


NVD link : CVE-2014-8750

Mitre link : CVE-2014-8750

CVE.ORG link : CVE-2014-8750


JSON object : View

Products Affected

openstack

  • nova
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')