CVE-2013-0326

Publication date 5 December 2019

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

5.5 · Medium

Score breakdown

OpenStack nova base images permissions are world readable

Read the notes from the security team

Status

Package Ubuntu Release Status
nova 14.04 LTS trusty Not in release
13.10 saucy Ignored
12.10 quantal Ignored
12.04 LTS precise Ignored
10.04 LTS lucid Not in release

Notes


seth-arnold

/var/lib/nova/instances/_base/ apparently stores images with DAC permissions set to 0644. Deferred while waiting for upstream to address the issue -- I suspect the fix is simple, but the consequences may not be.


jdstrand

Ignoring. VMs are confined by AppArmor and are not able to read each other's files. Even if this were not the case, the files would be readable by the the libvirt-qemu:kvm user, so changing the permissions to 0640 would not help greatly. Therefore the protection would only be against other users on the system and a typical production Nova installation will not have these types of users or extra services. Furthermore, changing the permissions in a security update could be disruptive to production systems on upgrade. no upstream fix as of 2014-05-05

Severity score breakdown

Parameter Value
Base score 5.5 · Medium
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact None
Availability impact None
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N