National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

CVE-2012-5625 Detail

Description

OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by reading the memory of the previous logical volume (LV).

Source:  MITRE
Description Last Modified:  12/26/2012

Impact

CVSS v2.0 Severity and Metrics:

Base Score: 4.3 MEDIUM
Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N) (V2 legend)
Impact Subscore: 2.9
Exploitability Subscore: 8.6


Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (AU): None
Confidentiality (C): Partial
Integrity (I): None
Availability (A): None
Additional Information:
Allows unauthorized disclosure of information

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.

Hyperlink Resource
http://rhn.redhat.com/errata/RHSA-2013-0208.html
http://www.openwall.com/lists/oss-security/2012/12/11/5
http://www.securityfocus.com/bid/56904
http://www.ubuntu.com/usn/USN-1663-1 Patch
https://bugs.launchpad.net/nova/+bug/1070539
https://bugzilla.redhat.com/show_bug.cgi?id=884293
https://github.com/openstack/nova/commit/9d2ea970422591f8cdc394001be9a2deca499a5f Patch
https://github.com/openstack/nova/commit/a99a802e008eed18e39fc1d98170edc495cbd354 Patch
https://launchpad.net/nova/folsom/2012.2.2

Technical Details

Vulnerability Type (View All)

  • Information Leak / Disclosure (CWE-200)

Change History

1 change record found - show changes

Quick Info

CVE Dictionary Entry:
CVE-2012-5625
NVD Published Date:
12/26/2012
NVD Last Modified:
02/15/2013