CVE-2013-1664
Publication date 19 February 2013
Last updated 24 July 2024
Ubuntu priority
The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack.
Status
Package | Ubuntu Release | Status |
---|---|---|
cinder | ||
keystone | ||
nova | ||
python-django | ||
quantum | ||
Notes
jdstrand
Keystone on 11.10 is a pre-release version and unusable with other components such as nova and horizon quantum will be fixed in grizzly rc1, due out the 2nd week of March
Patch details
Package | Patch details |
---|---|
python-django | |
quantum |
References
Related Ubuntu Security Notices (USN)
- USN-1731-1
- OpenStack Cinder vulnerability
- 21 February 2013
- USN-1757-1
- Django vulnerabilities
- 7 March 2013
- USN-1730-1
- OpenStack Keystone vulnerabilities
- 20 February 2013
- USN-1734-1
- OpenStack Nova vulnerability
- 21 February 2013