Bug 814275 - CVE-2012-2101 openstack-nova: No quota enforced on security group rules [fedora-17]
Summary: CVE-2012-2101 openstack-nova: No quota enforced on security group rules [fedo...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: openstack-nova
Version: 17
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Pádraig Brady
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks: CVE-2012-2101
TreeView+ depends on / blocked
 
Reported: 2012-04-19 14:09 UTC by Pádraig Brady
Modified: 2016-01-04 14:42 UTC (History)
13 users (show)

Fixed In Version: openstack-nova-2012.1-2.fc17
Clone Of:
Environment:
Last Closed: 2012-05-02 04:45:59 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Pádraig Brady 2012-04-19 14:09:41 UTC
please see the bug #813768 for more details on this vulnerability

Comment 1 Jan Lieskovsky 2012-04-19 16:37:33 UTC
Thank you for this bug report, Pádraig. Have opened #813768 for public audience.

From what I can tell from looking at the proposed upstream patch:
https://bugzilla.redhat.com/show_bug.cgi?id=813768#c0

this issue would affect the versions of the openstack-nova package, as shipped with Fedora release of 16 and Fedora EPEL 6 (though the proposed patch would need to be backported to apply gracefully against these versions). Are these assumptions correct? Could you confirm that? (so I could create trackers for Fedora-16 and Fedora EPEL-6 openstack-nova package versions too).

Thank you, Jan.

Comment 2 Fedora Update System 2012-04-19 20:01:19 UTC
openstack-nova-2012.1-2.fc17 has been submitted as an update for Fedora 17.
https://admin.fedoraproject.org/updates/openstack-nova-2012.1-2.fc17

Comment 3 Fedora Update System 2012-04-20 06:03:21 UTC
Package openstack-nova-2012.1-2.fc17:
* should fix your issue,
* was pushed to the Fedora 17 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing openstack-nova-2012.1-2.fc17'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-2012-6273/openstack-nova-2012.1-2.fc17
then log in and leave karma (feedback).

Comment 4 Fedora Update System 2012-05-02 04:45:59 UTC
openstack-nova-2012.1-2.fc17 has been pushed to the Fedora 17 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.