—
PYSEC-2012-42
상세
OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by reading the memory of the previous logical volume (LV).
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
PyPI / nova
No fixed version published yet for nova (pip). Pin to a known-safe version or switch to an alternative.
참고
- http://osvdb.org/88419 [WEB]
- http://www.openwall.com/lists/oss-security/2012/12/11/5 [WEB]
- http://www.securityfocus.com/bid/56904 [WEB]
- https://bugs.launchpad.net/nova/+bug/1070539 [WEB]
- https://launchpad.net/nova/folsom/2012.2.2 [WEB]
- http://rhn.redhat.com/errata/RHSA-2013-0208.html [ADVISORY]
- https://bugzilla.redhat.com/show_bug.cgi?id=884293 [REPORT]
- http://www.ubuntu.com/usn/USN-1663-1 [FIX]
- https://github.com/openstack/nova/commit/9d2ea970422591f8cdc394001be9a2deca499a5f [FIX]
- https://github.com/openstack/nova/commit/a99a802e008eed18e39fc1d98170edc495cbd354 [FIX]