First published: Wed Apr 03 2013(Updated: )
The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/Django | >=1.4.0<1.4.4 | 1.4.4 |
pip/Django | >=1.3.0<1.3.6 | 1.3.6 |
OpenStack Cinder Folsom | ||
OpenStack Compute (nova) Essex | ||
OpenStack Compute (nova) Folsom | ||
OpenStack Folsom | ||
OpenStack Grizzly | ||
OpenStack Keystone |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1664 is classified as a medium severity vulnerability due to the potential for denial of service attacks.
To resolve CVE-2013-1664, upgrade to Django versions 1.4.4 or 1.3.6, or update the affected OpenStack components to their latest versions.
CVE-2013-1664 affects multiple versions of Python XML libraries in Python 2.6 through 3.4 and various OpenStack components including Keystone and Nova.
CVE-2013-1664 allows remote attackers to conduct denial of service attacks by exploiting the vulnerabilities in XML processing.
Yes, OpenStack Keystone, Nova, Cinder, and versions Folsom and Grizzly are specifically mentioned as affected by CVE-2013-1664.