Red Hat Security Advisory: openstack-nova security, bug fix, and enhancement update
🔗 CVE IDs covered (3)
📋 Description
CVE-2014-3708 — openstack-nova: Nova network denial of service through API filtering CVE-2014-8333 — openstack-nova: Nova VMware instance in resize state may leak CVE-2015-0259 — openstack-nova: console Cross-Site WebSocket hijacking
🎯 Affected products17
- Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6
- openstack-nova-0:2014.1.4-3.el6ost.noarch as a component of Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6
- openstack-nova-0:2014.1.4-3.el6ost.src as a component of Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6
- openstack-nova-api-0:2014.1.4-3.el6ost.noarch as a component of Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6
- openstack-nova-cells-0:2014.1.4-3.el6ost.noarch as a component of Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6
- openstack-nova-cert-0:2014.1.4-3.el6ost.noarch as a component of Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6
- openstack-nova-common-0:2014.1.4-3.el6ost.noarch as a component of Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6
- openstack-nova-compute-0:2014.1.4-3.el6ost.noarch as a component of Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6
- openstack-nova-conductor-0:2014.1.4-3.el6ost.noarch as a component of Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6
- openstack-nova-console-0:2014.1.4-3.el6ost.noarch as a component of Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6
- openstack-nova-doc-0:2014.1.4-3.el6ost.noarch as a component of Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6
- openstack-nova-network-0:2014.1.4-3.el6ost.noarch as a component of Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6
- openstack-nova-novncproxy-0:2014.1.4-3.el6ost.noarch as a component of Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6
- openstack-nova-objectstore-0:2014.1.4-3.el6ost.noarch as a component of Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6
- openstack-nova-scheduler-0:2014.1.4-3.el6ost.noarch as a component of Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6
- openstack-nova-serialproxy-0:2014.1.4-3.el6ost.noarch as a component of Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6
- python-nova-0:2014.1.4-3.el6ost.noarch as a component of Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6
✅ Remediation
Before applying this update, ensure all previously released errata relevant to your system have been applied. Red Hat Enterprise Linux OpenStack Platform 5 for RHEL 6 runs on Red Hat Enterprise Linux 6.6. The Red Hat Enterprise Linux OpenStack Platform 5 for RHEL 6 Release Notes (see References section) contain the following: * An explanation of the way in which the provided components interact to form a working cloud computing environment. * Technology Previews, Recommended Practices, and Known Issues. * The channels required for Red Hat Enterprise Linux OpenStack Platform 5 for RHEL 6, including which channels need to be enabled and disabled. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2015:0844
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Linux_OpenStack_Platform/5/html/Technical_Notes/index.html
- externalhttps://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Linux_OpenStack_Platform/5/html/Release_Notes/index.html
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1154890
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1154951
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1170558
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1174424
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1180602
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1190112
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2015/rhsa-2015_0844.json