Bug 991630 (CVE-2013-4202) - CVE-2013-4202 OpenStack: Cinder Denial of Service using XML entities
Summary: CVE-2013-4202 OpenStack: Cinder Denial of Service using XML entities
Alias: CVE-2013-4202
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
Whiteboard: impact=moderate,public=20130808,repor...
Depends On: 991631 995183 995184 995185 995187
Blocks: 991632
TreeView+ depends on / blocked
Reported: 2013-08-03 04:56 UTC by Kurt Seifried
Modified: 2019-06-08 19:40 UTC (History)
14 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Last Closed: 2014-03-10 06:24:34 UTC

Attachments (Terms of Use)
cinder-grizzly-CVE-2013-4202.patch (1.26 KB, patch)
2013-08-03 04:59 UTC, Kurt Seifried
no flags Details | Diff
cinder-master-CVE-2013-4202.patch (2.54 KB, patch)
2013-08-03 05:00 UTC, Kurt Seifried
no flags Details | Diff

System ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2013:1198 normal SHIPPED_LIVE Moderate: openstack-cinder security update 2013-09-04 00:17:02 UTC

Description Kurt Seifried 2013-08-03 04:56:41 UTC
Thierry	Carrez (thierry@openstack.org) reports:

Title: Denial of Service using XML entities in Nova/Cinder extensions
Reporter: Grant Murphy (Red Hat)
Products: Nova, Cinder
Affects: Grizzly and later

Grant Murphy from Red Hat reported that vulnerabilities in XML request
parsers were not fully patched in OSSA 2013-004. By leveraging XML
entity expansion in specific extensions, an unauthenticated attacker may
still consume excessive resources on the Nova or Cinder API servers,
resulting in a denial of service and potentially a crash. Only Nova
setups making use of the security group extension in Grizzly are
affected. Only Cinder setups making use of the backups or volume
transfer API extension in Grizzly are affected.

Proposed patches:
See attached patches. Unless a flaw is discovered in them, these patches
will be merged to Nova & Cinder master (havana) and stable/grizzly
branches on the public disclosure date.

Please note that this was originally assigned a	single CVE. It has since
been split into two CVE's (CVE-2013-4179 continues to be used for Nova and 
CVE-2013-4202 should be used for Cinder).

Comment 2 Kurt Seifried 2013-08-03 04:59:55 UTC
Created attachment 782217 [details]

Comment 3 Kurt Seifried 2013-08-03 05:00:27 UTC
Created attachment 782218 [details]

Comment 6 Kurt Seifried 2013-08-08 17:45:29 UTC
Created openstack-cinder tracking bugs for this issue:

Affects: fedora-all [bug 995183]
Affects: epel-6 [bug 995184]

Comment 7 Murray McAllister 2013-09-02 16:26:33 UTC

This issue was discovered by Grant Murphy of the Red Hat Product Security Team.

Comment 8 errata-xmlrpc 2013-09-03 20:23:28 UTC
This issue has been addressed in following products:

  OpenStack 3 for RHEL 6

Via RHSA-2013:1198 https://rhn.redhat.com/errata/RHSA-2013-1198.html

Note You need to log in before you can comment on or make changes to this bug.