CVE-2013-7130
high
CVSS v3
—
CVSS v2
7.1
VIR risk
7.1
Description
The i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack Compute (Nova) Grizzly, Havana, and Icehouse, when using KVM live block migration, does not properly create all expected files, which allows attackers to obtain snapshot root disk contents of other users via ephemeral storage.
Predictions
Exploit likelihood
30%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-7130
Vendor advisory: cve@mitre.org — https://review.openstack.org/#/c/68660/
Vendor advisory: cve@mitre.org — https://review.openstack.org/#/c/68658/
Vendor advisory: cve@mitre.org — http://secunia.com/advisories/56450
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 2013.2.2 |
| debian | bullseye | fixed | 2013.2.2 |
| debian | forky | fixed | 2013.2.2 |
| debian | sid | fixed | 2013.2.2 |
| debian | trixie | fixed | 2013.2.2 |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| PyPI | nova | <12.0.0a0 | 12.0.0a0 |
References
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127732.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127735.html
- http://osvdb.org/102416
- http://rhn.redhat.com/errata/RHSA-2014-0231.html
- http://secunia.com/advisories/56450
- http://www.openwall.com/lists/oss-security/2014/01/23/5
- http://www.securityfocus.com/bid/65106
- http://www.ubuntu.com/usn/USN-2247-1
- https://bugs.launchpad.net/nova/+bug/1251590
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90652
- https://review.openstack.org/#/c/68658/
- https://review.openstack.org/#/c/68659/
- https://review.openstack.org/#/c/68660/
- https://nvd.nist.gov/vuln/detail/CVE-2013-7130
- https://github.com/openstack/nova/commit/15ee7e17f63f5583307a546ecf28952c364c88f9
- https://github.com/openstack/nova/commit/b0d36683fe064b32cbef013e1c0c46bd018ab9a1
- https://github.com/openstack/nova/commit/cbeb5e51886b0296349fc476305bfe3d63c627c3
- https://github.com/openstack/nova
- https://github.com/pypa/advisory-database/tree/main/vulns/nova/PYSEC-2014-111.yaml
- https://review.openstack.org/#/c/68658
- https://review.openstack.org/#/c/68659
- https://review.openstack.org/#/c/68660
- https://security-tracker.debian.org/tracker/CVE-2013-7130
CWEs
CWE-200
Verify integrity in audit chain (admin only). AS-IS.