CVE-2014-3608
06.10.2014, 14:55
The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2573.Enginsight
Vendor | Product | Version |
---|---|---|
openstack | nova | 2013.2 ≤ 𝑥 ≤ 2013.2.4 |
openstack | nova | 2014.1 ≤ 𝑥 < 2014.1.3 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References