CVE-2014-3517
Publication date 7 August 2014
Last updated 24 July 2024
Ubuntu priority
api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, when proxying metadata requests through Neutron, makes it easier for remote attackers to guess instance ID signatures via a brute-force attack that relies on timing differences in responses to instance metadata requests.
Status
Package | Ubuntu Release | Status |
---|---|---|
nova | 14.04 LTS trusty |
Fixed 1:2014.1.2-0ubuntu1
|
Notes
Patch details
Package | Patch details |
---|---|
nova |
|
References
Related Ubuntu Security Notices (USN)
- USN-2325-1
- OpenStack Nova vulnerability
- 21 August 2014