CVE-2012-3361
Publication date 3 July 2012
Last updated 24 July 2024
Ubuntu priority
virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image.
Notes
tyhicks
Per OpenStack Vuln Mgmt Team, all Nova versions are affected The fix for this CVE was incomplete, see CVE-2012-3447
References
Related Ubuntu Security Notices (USN)
- USN-1497-1
- Nova vulnerabilities
- 3 July 2012