CVE-2012-3371
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The Nova scheduler in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when DifferentHostFilter or SameHostFilter is enabled, allows remote authenticated users to cause a denial of service (excessive database lookup calls and server hang) via a request with many repeated IDs in the os:scheduler_hints section.
El planificador Nova en OpenStack Compute (Nova) Folsom (2012.2) y Essex (2012.1), cuando DifferentHostFilter o SameHostFilter están activados, permite a usuarios remotos autenticados provocar una denegación de servicio (exceso de llamadas de búsqueda de base de datos y el servidor se bloquea) a través de una solicitud con muchos identificadores repetidos en el sistema operativo: Sección scheduler_hints.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-06-14 CVE Reserved
- 2012-07-12 CVE Published
- 2023-12-13 EPSS Updated
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2012/07/11/13 | Mailing List | |
http://www.securityfocus.com/bid/54388 | Vdb Entry | |
https://lists.launchpad.net/openstack/msg14452.html | Mailing List |
URL | Date | SRC |
---|---|---|
https://bugs.launchpad.net/nova/+bug/1017795 | 2024-08-06 | |
https://github.com/openstack/nova/commit/034762e8060dcf0a11cb039b9d426b0d0bb1801d | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.ubuntu.com/usn/USN-1501-1 | 2012-08-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openstack Search vendor "Openstack" | Compute Search vendor "Openstack" for product "Compute" | 2012.2 Search vendor "Openstack" for product "Compute" and version "2012.2" | - |
Affected
| ||||||
Openstack Search vendor "Openstack" | Essex Search vendor "Openstack" for product "Essex" | 2012.1 Search vendor "Openstack" for product "Essex" and version "2012.1" | - |
Affected
| ||||||
Openstack Search vendor "Openstack" | Folsom Search vendor "Openstack" for product "Folsom" | 2012.2 Search vendor "Openstack" for product "Folsom" and version "2012.2" | - |
Affected
|