OpenStack Nova XML Parsing CVE-2013-4179 Multiple Denial of Service Vulnerabilities
BID:61692
Info
OpenStack Nova XML Parsing CVE-2013-4179 Multiple Denial of Service Vulnerabilities
| Bugtraq ID: | 61692 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2013-4179 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 08 2013 12:00AM |
| Updated: | Apr 13 2015 09:36PM |
| Credit: | Grant Murphy |
| Vulnerable: |
Ubuntu Ubuntu Linux 13.04 Ubuntu Ubuntu Linux 12.10 Ubuntu Ubuntu Linux 12.04 LTS OpenStack OpenStack Compute (Nova) 2013.1.2 OpenStack OpenStack Compute (Nova) 2013.1 OpenStack OpenStack Compute (Nova) 2012.2.4 OpenStack OpenStack Compute (Nova) 2012.2 OpenStack OpenStack Compute (Nova) 2012.1.2 OpenStack OpenStack Compute (Nova) 2012.1 OpenStack OpenStack Compute (Nova) 2011.3 |
| Not Vulnerable: |
OpenStack OpenStack Compute (Nova) 2013.1.3 |
Discussion
OpenStack Nova XML Parsing CVE-2013-4179 Multiple Denial of Service Vulnerabilities
OpenStack Nova is prone to multiple denial-of-service vulnerabilities.
Successful exploits may allow an attacker to cause an affected application to consume excessive amounts of memory and cause a crash, resulting in a denial-of-service condition.
OpenStack Nova is prone to multiple denial-of-service vulnerabilities.
Successful exploits may allow an attacker to cause an affected application to consume excessive amounts of memory and cause a crash, resulting in a denial-of-service condition.
Exploit / POC
OpenStack Nova XML Parsing CVE-2013-4179 Multiple Denial of Service Vulnerabilities
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
OpenStack Nova XML Parsing CVE-2013-4179 Multiple Denial of Service Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
OpenStack Nova XML Parsing CVE-2013-4179 Multiple Denial of Service Vulnerabilities
References:
References:
- [OSSA 2013-023] Potential unsafe XML usage (CVE-2013-4179, CVE-2013-4202) (Grant Murphy)
- Bug 989707 - (CVE-2013-4179) CVE-2013-4179 OpenStack: Nova XML entities DoS (Red Hat)
- Change I43afb2e1: Remove unsafe XML parsing (OpenStack)
- Change I43afb2e1: Remove unsafe XML parsing (OpenStack)
- OpenStack Homepage (OpenStack)
- USN-2000-1: Nova vulnerabilities (Ubuntu)
- USN-2005-1: Cinder vulnerabilities (Ubuntu)