Security update for openstack-nova

SUSE Security Update: Security update for openstack-nova
Announcement ID: SUSE-SU-2013:1292-1
Rating: moderate
References: #817181 #821879 #829068
Affected Products:
  • SUSE Cloud 1.0

  • An update that solves one vulnerability and has two fixes is now available.

    Description:


    A local DoS condition in openstack-nova's qcow2 virtual
    image size handling has been fixed. CVE-2013-2096 was
    assigned to this issue.

    Security Issue reference:

    * CVE-2013-2096
    >

    Patch Instructions:

    To install this SUSE Security Update use YaST online_update.
    Alternatively you can run the command listed for your product:

    • SUSE Cloud 1.0:
      zypper in -t patch sleclo10sp2-openstack-nova-8097

    To bring your system up-to-date, use "zypper patch".

    Package List:

    • SUSE Cloud 1.0 (x86_64):
    • openstack-nova-2012.1+git.1364234478.e52e691-0.7.1
    • openstack-nova-api-2012.1+git.1364234478.e52e691-0.7.1
    • openstack-nova-cert-2012.1+git.1364234478.e52e691-0.7.1
    • openstack-nova-compute-2012.1+git.1364234478.e52e691-0.7.1
    • openstack-nova-network-2012.1+git.1364234478.e52e691-0.7.1
    • openstack-nova-objectstore-2012.1+git.1364234478.e52e691-0.7.1
    • openstack-nova-scheduler-2012.1+git.1364234478.e52e691-0.7.1
    • openstack-nova-vncproxy-2012.1+git.1364234478.e52e691-0.7.1
    • openstack-nova-volume-2012.1+git.1364234478.e52e691-0.7.1
    • python-nova-2012.1+git.1364234478.e52e691-0.7.1

    References:

    • http://support.novell.com/security/cve/CVE-2013-2096.html
    • https://bugzilla.novell.com/817181
    • https://bugzilla.novell.com/821879
    • https://bugzilla.novell.com/829068
    • http://download.suse.com/patch/finder/?keywords=e57190d51898cdc8d8e87a413912b595