CVE-2012-3447
Publication date 10 August 2012
Last updated 4 August 2025
Ubuntu priority
Description
virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom before Folsom-3 allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image that uses a symlink that is only readable by root. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3361.
Status
| Package | Ubuntu Release | Status | 
|---|---|---|
| nova | 12.10 quantal | 
                              
                               
                                Not affected 
                                
                               
                             |      
                          
                            
                          
                        
                      
| 12.04 LTS precise | 
                              
                               
                                Fixed 2012.1+stable~20120612-3ee026e-0ubuntu1.3 
                                
                               
                             |      
                          
                            
                          
                        
                      |
| 11.10 oneiric | 
                              
                               
                                Fixed 2011.3-0ubuntu6.10 
                                
                               
                             |      
                          
                            
                          
                        
                      |
| 11.04 natty | Ignored end of life | |
| 10.04 LTS lucid | Not in release | |
| 8.04 LTS hardy | Not in release | 
Patch details
| Package | Patch details | 
|---|---|
| nova | 
                        
  | 
                    
References
Related Ubuntu Security Notices (USN)
- USN-1545-1
 - Nova vulnerability
 - 22 August 2012