CVE-2013-1664
published 2013-04-03CVE-2013-1664: The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom…
PriorityP425medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
4.86%
91.1th percentile
The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | cinder | < cinder 2013.1.2-4 (bookworm) | cinder 2013.1.2-4 (bookworm) |
| debian | cinder | < cinder 2012.2.3-1 (bookworm) | cinder 2012.2.3-1 (bookworm) |
| debian | keystone | < cinder 2012.2.3-1 (bookworm) | cinder 2012.2.3-1 (bookworm) |
| debian | nova | < nova 2013.1.3-1 (bookworm) | nova 2013.1.3-1 (bookworm) |
| debian | nova | < cinder 2012.2.3-1 (bookworm) | cinder 2012.2.3-1 (bookworm) |
| djangoproject | django | >= 1.3.0 < 1.3.6 | 1.3.6 |
| djangoproject | django | >= 1.4.0 < 1.4.4 | 1.4.4 |
| openstack | cinder | >= 0 < 2012.2.3-1 | 2012.2.3-1 |
| openstack | cinder | >= 0 < 2013.1.2-4 | 2013.1.2-4 |
| openstack | cinder | >= 0 < 2012.2.3-1 | 2012.2.3-1 |
| openstack | cinder | >= 0 < 2013.1.2-4 | 2013.1.2-4 |
| openstack | cinder | >= 0 < 2012.2.3-1 | 2012.2.3-1 |
| openstack | cinder | >= 0 < 2013.1.2-4 | 2013.1.2-4 |
| openstack | cinder | >= 0 < 2012.2.3-1 | 2012.2.3-1 |
| openstack | cinder | >= 0 < 2013.1.2-4 | 2013.1.2-4 |
| openstack | cinder | >= 0 < 7.0.0a0 | 7.0.0a0 |
| openstack | cinder | 2013.1 – 2013.1.3 | — |
| openstack | compute | — | — |
| openstack | havana | <= havana-2 | — |
| openstack | havana | — | — |
| openstack | keystone | >= 0 < 2012.1.1-13 | 2012.1.1-13 |
| openstack | keystone | >= 0 < 2012.1.1-13 | 2012.1.1-13 |
| openstack | keystone | >= 0 < 2012.1.1-13 | 2012.1.1-13 |
| openstack | keystone | >= 0 < 2012.1.1-13 | 2012.1.1-13 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
ghsa5.0MEDIUM
osv5.0MEDIUM
vendor_ubuntu6.4MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
OpenStack: Nova XML entities DoS
vendor_redhat·2013-08-08·CVSS 5.0
CVE-2013-4179 [MEDIUM] CWE-776 OpenStack: Nova XML entities DoS
OpenStack: Nova XML entities DoS
The security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havana before havana-3, and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.
Package: openstack-nova (Red Hat OpenStack Platform 4) - Affected
Red Hat
OpenStack: Cinder Denial of Service using XML entities
vendor_redhat·2013-08-08·CVSS 5.0
CVE-2013-4202 [MEDIUM] OpenStack: Cinder Denial of Service using XML entities
OpenStack: Cinder Denial of Service using XML entities
The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_transfer.py) APIs in OpenStack Cinder Grizzly 2013.1.3 and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.
Package: openstack-cinder (Red Hat OpenStack Platform 4) - Affected
Ubuntu
Django vulnerabilities
vendor_ubuntu·2013-03-07·CVSS 6.4
CVE-2012-4520 [MEDIUM] Django vulnerabilities
Title: Django vulnerabilities
Summary: Several security issues were fixed in Django.
James Kettle discovered that Django did not properly filter the Host HTTP
header when processing certain requests. An attacker could exploit this to
generate and display arbitrary URLs to users. Although this issue had been
previously addressed in USN-1632-1, this update adds additional hardening
measures to host header validation. This update also adds a new
ALLOWED_HOSTS setting that can be set to a list of acceptable values for
headers. (CVE-2012-4520)
Orange Tsai discovered that Django incorrectly performed permission checks
when displaying the history view in the admin interface. An administrator
could use this flaw to view the history of any object, regardless of
intended permissions. (CVE-2013-03
Ubuntu
OpenStack Cinder vulnerability
vendor_ubuntu·2013-02-21·CVSS 5.0
CVE-2013-1664 [MEDIUM] OpenStack Cinder vulnerability
Title: OpenStack Cinder vulnerability
Summary: Cinder could be made to crash if it received specially crafted input.
Stuart Stent discovered that Cinder would allow XML entity processing. A
remote unauthenticated attacker could exploit this using the Cinder API to
cause a denial of service via resource exhaustion. (CVE-2013-1664)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
OpenStack Nova vulnerability
vendor_ubuntu·2013-02-21·CVSS 5.0
CVE-2013-1664 [MEDIUM] OpenStack Nova vulnerability
Title: OpenStack Nova vulnerability
Summary: Nova could be made to crash if it received specially crafted input.
Joshua Harlow discovered that Nova would allow XML entity processing. A
remote unauthenticated attacker could exploit this using the Nova API to
cause a denial of service via resource exhaustion. (CVE-2013-1664)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
OpenStack Keystone vulnerabilities
vendor_ubuntu·2013-02-20·CVSS 5.0
CVE-2013-0282 [MEDIUM] OpenStack Keystone vulnerabilities
Title: OpenStack Keystone vulnerabilities
Summary: Keystone could be made to crash or expose sensitive information over the
network.
Nathanael Burton discovered that Keystone did not properly verify disabled
users. An authenticated but disabled user would continue to have access
rights that were removed. (CVE-2013-0282)
Jonathan Murray discovered that Keystone would allow XML entity processing.
A remote unauthenticated attacker could exploit this to cause a denial of
service via resource exhaustion. Authenticated users could also use this to
view arbitrary files on the Keystone server. (CVE-2013-1664, CVE-2013-1665)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bindings: Internal entity expansion in Python XML libraries inflicts DoS vulnerabilities
vendor_redhat·2013-02-19·CVSS 5.0
CVE-2013-1664 [MEDIUM] bindings: Internal entity expansion in Python XML libraries inflicts DoS vulnerabilities
bindings: Internal entity expansion in Python XML libraries inflicts DoS vulnerabilities
The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack.
Statement: This issue affects the versions of python as shipped with Red Hat Enterprise Linux 5, 6 and 7. Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates.
Package: python (Red Hat Enterprise Linux 5) - Will not fix
Package: python (Red Hat Enterprise Linux 6) - Will not
Debian
CVE-2013-4202: cinder - The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_...
vendor_debian·2013·CVSS 5.0
CVE-2013-4202 [MEDIUM] CVE-2013-4202: cinder - The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_...
The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_transfer.py) APIs in OpenStack Cinder Grizzly 2013.1.3 and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.
Scope: local
bookworm: resolved (fixed in 2013.1.2-4)
bullseye: resolved (fixed in 2013.1.2-4)
forky: resolved (fixed in 2013.1.2-4)
sid: resolved (fixed in 2013.1.2-4)
trixie: resolved (fixed in 2013.1.2-4)
Debian
CVE-2013-4179: nova - The security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havan...
vendor_debian·2013·CVSS 5.0
CVE-2013-4179 [MEDIUM] CVE-2013-4179: nova - The security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havan...
The security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havana before havana-3, and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.
Scope: local
bookworm: resolved (fixed in 2013.1.3-1)
bullseye: resolved (fixed in 2013.1.3-1)
forky: resolved (fixed in 2013.1.3-1)
sid: resolved (fixed in 2013.1.3-1)
trixie: resolved (fixed in 2013.1.3-1)
Debian
CVE-2013-1664: cinder - The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenSt...
vendor_debian·2013·CVSS 5.0
CVE-2013-1664 [MEDIUM] CVE-2013-1664: cinder - The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenSt...
The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack.
Scope: local
bookworm: resolved (fixed in 2012.2.3-1)
bullseye: resolved (fixed in 2012.2.3-1)
forky: resolved (fixed in 2012.2.3-1)
sid: resolved (fixed in 2012.2.3-1)
trixie: resolved (fixed in 2012.2.3-1)
OSV
OpenStack Compute (Nova) vulnerable to denial of service via XML Entity Expansion attack
osv·2022-05-17·CVSS 5.0
CVE-2013-4179 [MEDIUM] OpenStack Compute (Nova) vulnerable to denial of service via XML Entity Expansion attack
OpenStack Compute (Nova) vulnerable to denial of service via XML Entity Expansion attack
The security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havana before havana-3, and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.
GHSA
OpenStack Compute (Nova) vulnerable to denial of service via XML Entity Expansion attack
ghsa·2022-05-17·CVSS 5.0
CVE-2013-4179 [MEDIUM] CWE-119 OpenStack Compute (Nova) vulnerable to denial of service via XML Entity Expansion attack
OpenStack Compute (Nova) vulnerable to denial of service via XML Entity Expansion attack
The security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havana before havana-3, and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.
GHSA
XML Entity Expansion (XEE) in Django
ghsa·2022-05-17
CVE-2013-1664 [MEDIUM] CWE-611 XML Entity Expansion (XEE) in Django
XML Entity Expansion (XEE) in Django
The XML libraries for Python, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack.
OSV
XML Entity Expansion (XEE) in Django
osv·2022-05-17
CVE-2013-1664 [MEDIUM] XML Entity Expansion (XEE) in Django
XML Entity Expansion (XEE) in Django
The XML libraries for Python, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack.
OSV
OpenStack Cinder Denial of Service using XML entities
osv·2022-05-14·CVSS 5.0
CVE-2013-4202 [MEDIUM] OpenStack Cinder Denial of Service using XML entities
OpenStack Cinder Denial of Service using XML entities
The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_transfer.py) APIs in OpenStack Cinder Grizzly 2013.1.3 and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.
GHSA
OpenStack Cinder Denial of Service using XML entities
ghsa·2022-05-14·CVSS 5.0
CVE-2013-4202 [MEDIUM] OpenStack Cinder Denial of Service using XML entities
OpenStack Cinder Denial of Service using XML entities
The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_transfer.py) APIs in OpenStack Cinder Grizzly 2013.1.3 and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.
OSV
CVE-2013-4202: The (1) backup (api/contrib/backups
osv·2013-09-16·CVSS 5.0
CVE-2013-4202 [MEDIUM] CVE-2013-4202: The (1) backup (api/contrib/backups
The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_transfer.py) APIs in OpenStack Cinder Grizzly 2013.1.3 and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.
OSV
CVE-2013-4179: The security group extension in OpenStack Compute (Nova) Grizzly 2013
osv·2013-09-16·CVSS 5.0
CVE-2013-4179 [MEDIUM] CVE-2013-4179: The security group extension in OpenStack Compute (Nova) Grizzly 2013
The security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havana before havana-3, and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.
OSV
CVE-2013-1664: The XML libraries for Python 3
osv·2013-04-03·CVSS 5.0
CVE-2013-1664 [MEDIUM] CVE-2013-1664: The XML libraries for Python 3
The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1821 ruby: entity expansion DoS vulnerability in REXML
bugzilla·2013-02-22·CVSS 5.0
CVE-2013-1821 [MEDIUM] CVE-2013-1821 ruby: entity expansion DoS vulnerability in REXML
CVE-2013-1821 ruby: entity expansion DoS vulnerability in REXML
An unrestricted entity expansion flaw was reported in Ruby that can lead to a denial of service in REXML. When reading text nodes from an XML document, the REXML parser could be coerced into allocating extremely large string objects which could consume all available memory on the system.
Impacted code would look similar to the following:
document = REXML::Document.new some_xml_doc
document.root.text
In this case, when the 'text' method is called, entities will be expanded. An attacker could send a relatively small XML document that, when the entities were resolved, would consume extremely large amounts of memory on the target system. It is noted that this vulnerability is similar to the 'Billion Laughs' attack, and is also
Bugzilla
CVE-2013-1664 Python xml bindings: Internal entity expansion in Python XML libraries inflicts DoS vulnerabilities
bugzilla·2013-02-22·CVSS 5.0
CVE-2013-1664 [MEDIUM] CVE-2013-1664 Python xml bindings: Internal entity expansion in Python XML libraries inflicts DoS vulnerabilities
CVE-2013-1664 Python xml bindings: Internal entity expansion in Python XML libraries inflicts DoS vulnerabilities
Christian Heimes reports:
Entity declarations can contain more than just text for replacement.
billion laughs / exponential entity expansion
The Billion Laughs attack -- also known as exponential entity expansion --
uses multiple levels of nested entities. The original example uses 9 levels of
10 expansions in each level to expand the string lol to a string of 3 * 10 9
bytes, hence the name "billion laughs". The resulting string occupies 3 GB
(2.79 GiB) of memory; intermediate strings require additional memory. Because
most parsers don't cache the intermediate step for every expansion it is
repeated over and over again. It increases the CPU load even more.
An XML document
Bugzilla
Django: XML entity attacks
bugzilla·2013-02-20·CVSS 5.0
[MEDIUM] Django: XML entity attacks
Django: XML entity attacks
James Bennett of Django reports:
Django's serialization framework includes support for serializing to, and deserializing from, XML. Django's XML deserialization is vulnerable to entity-expansion and external-entity/DTD attacks.
To remedy this, Django's XML deserializer no longer allows DTDs, performs entity expansion, or fetches external entities/DTDs. Note that this only protects Django's XML serialization framework; if your application parses XML, we recommend you look into the defusedxml Python packages which remedy this for Python itself.
Because this issue also affects Python's XML libraries, it is covered by Python's CVE-2013-1664 and CVE-2013-1665.
External reference:
https://www.djangoproject.com/weblog/2013/feb/19/security/
Discussion:
Created Dja
Bugzilla
CVE-2013-1664 CVE-2013-1665 libxml2: DoS (excessive CPU consumption) by performing string substitutions during entities expansion [fedora-all]
bugzilla·2013-02-20·CVSS 5.0
CVE-2013-1664 [MEDIUM] CVE-2013-1664 CVE-2013-1665 libxml2: DoS (excessive CPU consumption) by performing string substitutions during entities expansion [fedora-all]
CVE-2013-1664 CVE-2013-1665 libxml2: DoS (excessive CPU consumption) by performing string substitutions during entities expansion [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and t
Bugzilla
CVE-2013-1664 CVE-2013-1665 libxml2: DoS (excessive CPU consumption) by performing string substitutions during entities expansion [fedora-all]
bugzilla·2013-02-20·CVSS 5.0
CVE-2013-1664 [MEDIUM] CVE-2013-1664 CVE-2013-1665 libxml2: DoS (excessive CPU consumption) by performing string substitutions during entities expansion [fedora-all]
CVE-2013-1664 CVE-2013-1665 libxml2: DoS (excessive CPU consumption) by performing string substitutions during entities expansion [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and t
Bugzilla
CVE-2013-1664 CVE-2013-1665 OpenStack keystone: XML entity parsing
bugzilla·2013-02-12·CVSS 5.0
CVE-2013-1664 [MEDIUM] CVE-2013-1664 CVE-2013-1665 OpenStack keystone: XML entity parsing
CVE-2013-1664 CVE-2013-1665 OpenStack keystone: XML entity parsing
Thierry Carrez ([email protected]) reports:
Title: Information leak and Denial of Service using XML entities
Reporter: Jonathan Murray (NCC Group), Joshua Harlow (Yahoo!), Stuart Stent
Products: Keystone, Nova, Cinder
Affects: All versions
Description:
Jonathan Murray from NCC Group, Joshua Harlow from Yahoo! and Stuart
Stent independently reported a vulnerability in the parsing of XML
requests in Keystone, Nova and Cinder. By using entities in XML
requests, an unauthenticated attacker may consume excessive resources on
the Keystone, Nova or Cinder API servers, resulting in a denial of
service and potentially a crash. Authenticated attackers may also
leverage XML entities to read the content of a local file on the
Ke
Bugzilla
CVE-2013-1664 CVE-2013-1665 OpenStack nova: XML entity parsing
bugzilla·2013-02-12·CVSS 5.0
CVE-2013-1664 [MEDIUM] CVE-2013-1664 CVE-2013-1665 OpenStack nova: XML entity parsing
CVE-2013-1664 CVE-2013-1665 OpenStack nova: XML entity parsing
Thierry Carrez ([email protected]) reports:
Title: Information leak and Denial of Service using XML entities
Reporter: Jonathan Murray (NCC Group), Joshua Harlow (Yahoo!), Stuart Stent
Products: Keystone, Nova, Cinder
Affects: All versions
Description:
Jonathan Murray from NCC Group, Joshua Harlow from Yahoo! and Stuart
Stent independently reported a vulnerability in the parsing of XML
requests in Keystone, Nova and Cinder. By using entities in XML
requests, an unauthenticated attacker may consume excessive resources on
the Keystone, Nova or Cinder API servers, resulting in a denial of
service and potentially a crash. This only affects servers with XML
support enabled.
Proposed patches:
See attached patches for current
Bugzilla
CVE-2013-1664 CVE-2013-1665 OpenStack cinder: XML entity parsing
bugzilla·2013-02-12·CVSS 5.0
CVE-2013-1664 [MEDIUM] CVE-2013-1664 CVE-2013-1665 OpenStack cinder: XML entity parsing
CVE-2013-1664 CVE-2013-1665 OpenStack cinder: XML entity parsing
Thierry Carrez ([email protected]) reports:
Title: Information leak and Denial of Service using XML entities
Reporter: Jonathan Murray (NCC Group), Joshua Harlow (Yahoo!), Stuart Stent
Products: Keystone, Nova, Cinder
Affects: All versions
Description:
Jonathan Murray from NCC Group, Joshua Harlow from Yahoo! and Stuart
Stent independently reported a vulnerability in the parsing of XML
requests in Keystone, Nova and Cinder. By using entities in XML
requests, an unauthenticated attacker may consume excessive resources on
the Keystone, Nova or Cinder API servers, resulting in a denial of
service and potentially a crash. This only affects servers with XML
support enabled.
Proposed patches:
See attached patches for curren
http://blog.python.org/2013/02/announcing-defusedxml-fixes-for-xml.htmlhttp://bugs.python.org/issue17239http://lists.openstack.org/pipermail/openstack-announce/2013-February/000078.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0657.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0658.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0670.htmlhttp://ubuntu.com/usn/usn-1757-1http://www.openwall.com/lists/oss-security/2013/02/19/2http://www.openwall.com/lists/oss-security/2013/02/19/4https://bugs.launchpad.net/nova/+bug/1100282http://blog.python.org/2013/02/announcing-defusedxml-fixes-for-xml.htmlhttp://bugs.python.org/issue17239http://lists.openstack.org/pipermail/openstack-announce/2013-February/000078.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0657.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0658.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0670.htmlhttp://ubuntu.com/usn/usn-1757-1http://www.openwall.com/lists/oss-security/2013/02/19/2http://www.openwall.com/lists/oss-security/2013/02/19/4https://bugs.launchpad.net/nova/+bug/1100282
2013-04-03
Published