Bug 989707 (CVE-2013-4179) - CVE-2013-4179 OpenStack: Nova XML entities DoS
Summary: CVE-2013-4179 OpenStack: Nova XML entities DoS
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2013-4179
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
: 973520 976208 (view as bug list)
Depends On: 991629 995171 995172 995173 995180
Blocks: 973515 989760
TreeView+ depends on / blocked
 
Reported: 2013-07-29 18:25 UTC by Kurt Seifried
Modified: 2023-05-13 00:12 UTC (History)
15 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2014-11-06 05:52:48 UTC
Embargoed:


Attachments (Terms of Use)
nova-grizzly-CVE-2013-4179.patch (9.46 KB, patch)
2013-08-03 05:00 UTC, Kurt Seifried
no flags Details | Diff
nova-master-CVE-2013-4179.patch (9.05 KB, patch)
2013-08-03 05:01 UTC, Kurt Seifried
no flags Details | Diff


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2013:1199 0 normal SHIPPED_LIVE Moderate: openstack-nova security and bug fix update 2013-09-04 00:16:56 UTC

Description Kurt Seifried 2013-07-29 18:25:29 UTC
Thierry Carrez (thierry) reports:

Title: Denial of Service using XML entities in Nova/Cinder extensions
Reporter: Grant Murphy (Red Hat)
Products: Nova, Cinder
Affects: Grizzly

Description:
Grant Murphy from Red Hat reported that vulnerabilities in XML request
parsers were not fully patched in OSSA 2013-004. By leveraging XML
entity expansion in specific extensions, an unauthenticated attacker
may still consume excessive resources on the Nova or Cinder API
servers, resulting in a denial of service and potentially a crash.
Only Nova setups making use of the security group extension in Grizzly
are affected. Only Cinder setups making use of the backups or volume
transfer API extension in Grizzly are affected.

References:
https://bugs.launchpad.net/cinder/+bug/1190229

Comment 1 Kurt Seifried 2013-08-03 04:53:52 UTC
Please note that this was originally assigned a	single CVE. It has since
been split into two CVE's (CVE-2013-4179 continues to be used for Nova and CVE-2013-4202 should be used for Cinder).

Comment 4 Kurt Seifried 2013-08-03 05:00:52 UTC
Created attachment 782219 [details]
nova-grizzly-CVE-2013-4179.patch

Comment 5 Kurt Seifried 2013-08-03 05:01:29 UTC
Created attachment 782220 [details]
nova-master-CVE-2013-4179.patch

Comment 6 Kurt Seifried 2013-08-08 02:04:24 UTC
*** Bug 976208 has been marked as a duplicate of this bug. ***

Comment 7 Kurt Seifried 2013-08-08 02:07:10 UTC
*** Bug 973520 has been marked as a duplicate of this bug. ***

Comment 9 Kurt Seifried 2013-08-08 17:29:03 UTC
Created openstack-nova tracking bugs for this issue:

Affects: fedora-all [bug 995172]
Affects: epel-6 [bug 995173]

Comment 11 Murray McAllister 2013-09-03 04:50:09 UTC
Acknowledgements:

This issue was discovered by Grant Murphy of the Red Hat Product Security Team.

Comment 12 errata-xmlrpc 2013-09-03 20:19:31 UTC
This issue has been addressed in following products:

  OpenStack 3 for RHEL 6

Via RHSA-2013:1199 https://rhn.redhat.com/errata/RHSA-2013-1199.html


Note You need to log in before you can comment on or make changes to this bug.