Bug 903013 (CVE-2014-3708) - VUL-0: CVE-2014-3708: openstack-nova: Nova network denial of service through API filtering
Summary: VUL-0: CVE-2014-3708: openstack-nova: Nova network denial of service through ...
Status: RESOLVED FIXED
Alias: CVE-2014-3708
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Deadline: 2014-11-27
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/110223/
Whiteboard: maint:released:sle11-sp3-cl4:60323
Keywords:
Depends on:
Blocks:
 
Reported: 2014-10-29 09:28 UTC by Sebastian Krahmer
Modified: 2015-02-19 03:09 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Swamp Workflow Management 2014-10-29 23:00:23 UTC
bugbot adjusting priority
Comment 2 Swamp Workflow Management 2014-11-13 13:21:54 UTC
An update workflow for this issue was started.
This issue was rated as moderate.
Please submit fixed packages until 2014-11-27.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/59645
Comment 7 Ralf Haferkamp 2014-11-28 14:47:00 UTC
AFAICS the fix is already in our package since October 30th. (It was just lacking a bug id :/):

This from the openstack-nova package in 
SUSE:SLE-11-SP3:Update:Cloud4:Test:Update:Test :

-------------------------------------------------------------------
Thu Oct 30 06:42:12 UTC 2014 -  cloud-devel@suse.de

- Update to version nova-2014.1.4.dev37.g27d624f:
  * Fixes DOS issue in instance list ip filter

-------------------------------------------------------------------

Which just got approve by QA some 30 minutes ago. So I guess there is no need to resubmit this, is there?
Comment 8 Johannes Segitz 2014-11-28 14:50:18 UTC
(In reply to Ralf Haferkamp from comment #7)
No, if it is in there then we can assign the bug to us and we take it from here. 

Everything should be that easy to fix ;)
Comment 10 Benjamin Brunner 2015-02-17 10:39:56 UTC
Update released. Resolved fixed.
Comment 11 Swamp Workflow Management 2015-02-19 03:09:37 UTC
SUSE-SU-2015:0324-1: An update that solves 5 vulnerabilities and has two fixes is now available.

Category: security (low)
Bug References: 867922,897815,898371,899190,899199,901087,903013
CVE References: CVE-2014-3608,CVE-2014-3708,CVE-2014-7230,CVE-2014-7231,CVE-2014-8750
Sources used:
SUSE Cloud 4 (src):    openstack-nova-2014.1.4.dev49-0.7.1, openstack-nova-doc-2014.1.4.dev49-0.7.1