CVE-2013-7048
Dashboard / Vulnerabilities / CVE-2013-7048
CVE-2013-7048
Published: 23 Jan 2014Last Modified: 7 Jul 2026
Aliases:
Summary:
Details: OpenStack Compute (Nova) Grizzly 2013.1.4, Havana 2013.2.1, and earlier uses world-writable and world-readable permissions for the temporary directory used to store live snapshots, which allows local users to read and modify live snapshots.
References: http://rhn.redhat.com/errata/RHSA-2014-0231.html, http://www.openwall.com/lists/oss-security/2014/01/13/2, https://bugs.launchpad.net/nova/+bug/1227027, http://www.openwall.com/lists/oss-security/2014/01/13/2, https://bugs.launchpad.net/nova/+bug/1227027, https://bugs.launchpad.net/nova/+bug/1227027
Affected packages
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
