CVE-2013-4261Improper Restriction of Operations within the Bounds of a Memory Buffer in Folsom

Severity
3.5LOWNVD
EPSS
0.6%
top 30.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 29
Latest updateMay 17

Description

OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during messaging, which allows remote attackers to cause a denial of service (connection pool consumption), as demonstrated using multiple requests that send long strings to an instance console and retrieving the console log.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 6.8 | Impact: 2.9

Affected Packages4 packages

Debianopenstack/nova< 2013.2-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-6h2f-6j38-qxpp: OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during m2022-05-17
OSV
CVE-2013-4261: OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during m2013-10-29
CVEList
CVE-2013-4261: OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during m2013-10-29

📋Vendor Advisories

3
Ubuntu
Nova vulnerabilities2013-10-23
Red Hat
OpenStack: openstack-nova-compute console-log DoS2013-08-20
Debian
CVE-2013-4261: nova - OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid fo...2013

💬Community

3
Bugzilla
CVE-2013-4261 openstack-nova: OpenStack: openstack-nova-compute console-log DoS [epel-6]2013-08-21
Bugzilla
CVE-2013-4261 openstack-nova: OpenStack: openstack-nova-compute console-log DoS [fedora-all]2013-08-21
Bugzilla
CVE-2013-4261 OpenStack: openstack-nova-compute console-log DoS2013-08-21
CVE-2013-4261 — Openstack Folsom vulnerability | cvebase