Vulnerability Information: - OpenStack Security Advisory: 2013-006 - CVE ID: CVE-2013-0335 - Date of Advisory: February 26, 2013 - Title: VNC proxy can connect to the wrong VM - Reporters: Loganathan Parthipan (HP), Rohit Karajgi (NTT Data) Products Affected: - Product: Nova - Affected Versions: All versions Description: - Users requesting a console for a VM and then deleting the VM could result in the console token connecting to a different VM if the VNC port is reused during the token's lifetime before expiration. Fixes: - Grizzly (Master): Review Link - Folsom (Stable): Review Link - Essex (Stable): Review Link References: - CVE Page - Launchpad Bug Report