Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-4261
HistoryAug 22, 2013 - 12:00 a.m.

CVE-2013-4261

2013-08-2200:00:00
ubuntu.com
ubuntu.com
15

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:N/I:N/A:P

EPSS

0.006

Percentile

78.4%

OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache
Qpid for the RPC backend, does not properly handle errors that occur during
messaging, which allows remote attackers to cause a denial of service
(connection pool consumption), as demonstrated using multiple requests that
send long strings to an instance console and retrieving the console log.

Notes

Author Note
jdstrand Ubuntu 13.04 has fix in raring-updates backward-compatibility breaking change deemed too intrusive for stable release update
OSVersionArchitecturePackageVersionFilename
ubuntu13.04noarchnova< 1:2013.1.3-0ubuntu1.1UNKNOWN

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:N/I:N/A:P

EPSS

0.006

Percentile

78.4%