Bug 1112499 (CVE-2014-3517)
Summary: | CVE-2014-3517 openstack-nova: timing attack issue allows access to other instances' configuration information | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Murray McAllister <mmcallis> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | abaron, aortega, apevec, ayoung, chrisw, dallan, gkotton, gmollett, jrusnack, lhh, markmc, ndipanov, rbryant, sclewis, security-response-team, vdanen, vkaigoro, vpopovic, yeylon |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: |
A side-channel timing attack flaw was found in Nova. An attacker could possibly use this flaw to guess valid instance ID signatures, giving them access to details of another instance, by analyzing the response times of requests for instance metadata. This issue only affected configurations that proxy metadata requests via Neutron.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2014-08-21 05:00:31 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1118179, 1120316, 1120951, 1120952, 1120953, 1120954, 1121804 | ||
Bug Blocks: | 1112500 |
Description
Murray McAllister
2014-06-24 05:09:37 UTC
Created openstack-nova tracking bugs for this issue: Affects: epel-6 [bug 1120951] Created openstack-nova tracking bugs for this issue: Affects: fedora-19 [bug 1120953] Affects: fedora-20 [bug 1120954] This issue has been addressed in following products: OpenStack 5 for RHEL 7 Via RHSA-2014:0940 https://rhn.redhat.com/errata/RHSA-2014-0940.html IssueDescription: A side-channel timing attack flaw was found in Nova. An attacker could possibly use this flaw to guess valid instance ID signatures, giving them access to details of another instance, by analyzing the response times of requests for instance metadata. This issue only affected configurations that proxy metadata requests via Neutron. This issue has been addressed in following products: OpenStack 4 for RHEL 6 Via RHSA-2014:1084 https://rhn.redhat.com/errata/RHSA-2014-1084.html |