CVE-2013-4261
published 2013-10-29CVE-2013-4261: OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during messaging…
PriorityP416low3.5CVSS 2.0
AVNACMAuSCNINAP
EPSS
1.74%
75.2th percentile
OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during messaging, which allows remote attackers to cause a denial of service (connection pool consumption), as demonstrated using multiple requests that send long strings to an instance console and retrieving the console log.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2013.2-1 (bookworm) | nova 2013.2-1 (bookworm) |
| openstack | folsom | <= - | — |
| openstack | grizzly | <= - | — |
| openstack | nova | >= 0 < 2013.2-1 | 2013.2-1 |
| openstack | nova | >= 0 < 2013.2-1 | 2013.2-1 |
| openstack | nova | >= 0 < 2013.2-1 | 2013.2-1 |
| openstack | nova | >= 0 < 2013.2-1 | 2013.2-1 |
| redhat | openstack | — | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv3.5LOW
vendor_ubuntu6.0MEDIUM
vendor_debian3.5LOW
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6h2f-6j38-qxpp: OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during m
ghsa_unreviewed·2022-05-17
CVE-2013-4261 [LOW] CWE-119 GHSA-6h2f-6j38-qxpp: OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during m
OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during messaging, which allows remote attackers to cause a denial of service (connection pool consumption), as demonstrated using multiple requests that send long strings to an instance console and retrieving the console log.
OSV
CVE-2013-4261: OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during m
osv·2013-10-29·CVSS 3.5
CVE-2013-4261 [LOW] CVE-2013-4261: OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during m
OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during messaging, which allows remote attackers to cause a denial of service (connection pool consumption), as demonstrated using multiple requests that send long strings to an instance console and retrieving the console log.
Ubuntu
Nova vulnerabilities
vendor_ubuntu·2013-10-23·CVSS 6.0
CVE-2013-2256 [MEDIUM] Nova vulnerabilities
Title: Nova vulnerabilities
Summary: Nova could be made to crash if it received specially crafted network
requests.
It was discovered that Nova did not properly enforce the is_public property
when determining flavor access. An authenticated attacker could exploit
this to obtain sensitive information in private flavors. This issue only
affected Ubuntu 12.10 and 13.10. (CVE-2013-2256, CVE-2013-4278)
Grant Murphy discovered that Nova would allow XML entity processing. A
remote unauthenticated attacker could exploit this using the Nova API to
cause a denial of service via resource exhaustion. This issue only
affected Ubuntu 13.10. (CVE-2013-4179)
Vishvananda Ishaya discovered that Nova inefficiently handled network
security group updates when Nova was configured to use nova-network. An
aut
Red Hat
OpenStack: openstack-nova-compute console-log DoS
vendor_redhat·2013-08-20·CVSS 3.5
CVE-2013-4261 [LOW] OpenStack: openstack-nova-compute console-log DoS
OpenStack: openstack-nova-compute console-log DoS
OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during messaging, which allows remote attackers to cause a denial of service (connection pool consumption), as demonstrated using multiple requests that send long strings to an instance console and retrieving the console log.
Package: openstack-nova (Red Hat OpenStack Platform 4) - Affected
Debian
CVE-2013-4261: nova - OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid fo...
vendor_debian·2013·CVSS 3.5
CVE-2013-4261 [LOW] CVE-2013-4261: nova - OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid fo...
OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during messaging, which allows remote attackers to cause a denial of service (connection pool consumption), as demonstrated using multiple requests that send long strings to an instance console and retrieving the console log.
Scope: local
bookworm: resolved (fixed in 2013.2-1)
bullseye: resolved (fixed in 2013.2-1)
forky: resolved (fixed in 2013.2-1)
sid: resolved (fixed in 2013.2-1)
trixie: resolved (fixed in 2013.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4261 openstack-nova: OpenStack: openstack-nova-compute console-log DoS [epel-6]
bugzilla·2013-08-21·CVSS 3.5
CVE-2013-4261 [LOW] CVE-2013-4261 openstack-nova: OpenStack: openstack-nova-compute console-log DoS [epel-6]
CVE-2013-4261 openstack-nova: OpenStack: openstack-nova-compute console-log DoS [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 trac
Bugzilla
CVE-2013-4261 openstack-nova: OpenStack: openstack-nova-compute console-log DoS [fedora-all]
bugzilla·2013-08-21·CVSS 3.5
CVE-2013-4261 [LOW] CVE-2013-4261 openstack-nova: OpenStack: openstack-nova-compute console-log DoS [fedora-all]
CVE-2013-4261 openstack-nova: OpenStack: openstack-nova-compute console-log DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note:
Bugzilla
CVE-2013-4261 OpenStack: openstack-nova-compute console-log DoS
bugzilla·2013-08-21·CVSS 3.5
CVE-2013-4261 [LOW] CVE-2013-4261 OpenStack: openstack-nova-compute console-log DoS
CVE-2013-4261 OpenStack: openstack-nova-compute console-log DoS
Jaroslav Henner ([email protected]) reports:
When console-log is run often enough, it seems to be causing death of nova-compute.
Discussion:
Created openstack-nova tracking bugs for this issue:
Affects: fedora-all [bug 999276]
Affects: epel-6 [bug 999277]
---
Upstream bug: https://bugs.launchpad.net/nova/+bug/1215091
---
Acknowledgements:
This issue was discovered by Jaroslav Henner of Red Hat.
---
This issue has been addressed in following products:
OpenStack 3 for RHEL 6
Via RHSA-2013:1199 https://rhn.redhat.com/errata/RHSA-2013-1199.html
http://rhn.redhat.com/errata/RHSA-2013-1199.htmlhttp://seclists.org/oss-sec/2013/q3/595https://bugs.launchpad.net/nova/+bug/1215091https://bugzilla.redhat.com/show_bug.cgi?id=999164https://bugzilla.redhat.com/show_bug.cgi?id=999271http://rhn.redhat.com/errata/RHSA-2013-1199.htmlhttp://seclists.org/oss-sec/2013/q3/595https://bugs.launchpad.net/nova/+bug/1215091https://bugzilla.redhat.com/show_bug.cgi?id=999164https://bugzilla.redhat.com/show_bug.cgi?id=999271
2013-10-29
Published