Bug 999271 (CVE-2013-4261) - CVE-2013-4261 OpenStack: openstack-nova-compute console-log DoS
Summary: CVE-2013-4261 OpenStack: openstack-nova-compute console-log DoS
Alias: CVE-2013-4261
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
Depends On: 999164 999272 999273 999274 999276 999277
Blocks: 999281
TreeView+ depends on / blocked
Reported: 2013-08-21 05:09 UTC by Kurt Seifried
Modified: 2021-02-17 07:24 UTC (History)
31 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Last Closed: 2014-06-23 12:44:11 UTC

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2013:1199 0 normal SHIPPED_LIVE Moderate: openstack-nova security and bug fix update 2013-09-04 00:16:56 UTC

Description Kurt Seifried 2013-08-21 05:09:01 UTC
Jaroslav Henner (jhenner@redhat.com) reports:

When console-log is run often enough, it seems to be causing death of nova-compute.

Comment 2 Kurt Seifried 2013-08-21 05:16:28 UTC
Created openstack-nova tracking bugs for this issue:

Affects: fedora-all [bug 999276]
Affects: epel-6 [bug 999277]

Comment 3 Kurt Seifried 2013-08-21 19:38:38 UTC
Upstream bug: https://bugs.launchpad.net/nova/+bug/1215091

Comment 4 Murray McAllister 2013-09-03 04:52:57 UTC

This issue was discovered by Jaroslav Henner of Red Hat.

Comment 5 errata-xmlrpc 2013-09-03 20:22:13 UTC
This issue has been addressed in following products:

  OpenStack 3 for RHEL 6

Via RHSA-2013:1199 https://rhn.redhat.com/errata/RHSA-2013-1199.html

Note You need to log in before you can comment on or make changes to this bug.