PT-2013-4887 · Openstack · Havana+1

Grant Murphy

·

Published

2013-09-16

·

Updated

2023-02-13

·

CVE-2013-4179

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions OpenStack Compute (Nova) versions 2013.1.3 and earlier, Havana versions before havana-3
Description The issue allows remote attackers to cause a denial of service, resulting in resource consumption and crash, via an XML Entity Expansion (XEE) attack. This is due to an incomplete fix for a previous issue.
Recommendations For OpenStack Compute (Nova) versions 2013.1.3 and earlier, update to a version that includes the complete fix for the issue. For Havana versions before havana-3, update to havana-3 or later to resolve the issue.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2013-4179
GHSA-J6XH-Q826-55JW
RHSA-2013:1199

Affected Products

Havana
Openstack Compute