cbcvebase.
CVE-2013-1664
published 2013-04-03

CVE-2013-1664: The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom…

medium5CVSS 3.1
AVNACLAuNCNINAP
The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debiancinder< cinder 2013.1.2-4 (bookworm)cinder 2013.1.2-4 (bookworm)
debiancinder< cinder 2012.2.3-1 (bookworm)cinder 2012.2.3-1 (bookworm)
debiankeystone< cinder 2012.2.3-1 (bookworm)cinder 2012.2.3-1 (bookworm)
debiannova< nova 2013.1.3-1 (bookworm)nova 2013.1.3-1 (bookworm)
debiannova< cinder 2012.2.3-1 (bookworm)cinder 2012.2.3-1 (bookworm)
djangoprojectdjango>= 1.3.0 < 1.3.61.3.6
djangoprojectdjango>= 1.4.0 < 1.4.41.4.4
openstackcinder>= 0 < 2012.2.3-12012.2.3-1
openstackcinder>= 0 < 2013.1.2-42013.1.2-4
openstackcinder>= 0 < 2012.2.3-12012.2.3-1
openstackcinder>= 0 < 2013.1.2-42013.1.2-4
openstackcinder>= 0 < 2012.2.3-12012.2.3-1
openstackcinder>= 0 < 2013.1.2-42013.1.2-4
openstackcinder>= 0 < 2012.2.3-12012.2.3-1
openstackcinder>= 0 < 2013.1.2-42013.1.2-4
openstackcinder>= 0 < 7.0.0a07.0.0a0
openstackcinder2013.1 – 2013.1.3
openstackcompute
openstackhavana<= havana-2
openstackhavana
openstackkeystone>= 0 < 2012.1.1-132012.1.1-13
openstackkeystone>= 0 < 2012.1.1-132012.1.1-13
openstackkeystone>= 0 < 2012.1.1-132012.1.1-13
openstackkeystone>= 0 < 2012.1.1-132012.1.1-13

CVSS provenance

nvd5.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
ghsa5.0MEDIUM
osv5.0MEDIUM