CVE-2013-1664: XEE
The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack.
Other sources
The XML libraries for Python, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1664?
CVE-2013-1664 is classified as a medium severity vulnerability due to the potential for denial of service attacks.
How do I fix CVE-2013-1664?
To resolve CVE-2013-1664, upgrade to Django versions 1.4.4 or 1.3.6, or update the affected OpenStack components to their latest versions.
Which versions are affected by CVE-2013-1664?
CVE-2013-1664 affects multiple versions of Python XML libraries in Python 2.6 through 3.4 and various OpenStack components including Keystone and Nova.
What type of attack does CVE-2013-1664 allow?
CVE-2013-1664 allows remote attackers to conduct denial of service attacks by exploiting the vulnerabilities in XML processing.
Are any OpenStack components specifically mentioned in CVE-2013-1664?
Yes, OpenStack Keystone, Nova, Cinder, and versions Folsom and Grizzly are specifically mentioned as affected by CVE-2013-1664.