First published: Mon Sep 16 2013(Updated: )
The (1) power and (2) ipmi_boot actions in the HostController in Foreman before 1.2.2 allow remote attackers to cause a denial of service (memory consumption) via unspecified input that is converted to a symbol.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenStack for IBM Power | =3.0 | |
The Foreman | <=1.2.1 | |
The Foreman | =1.2.0 | |
The Foreman | =1.2.0-rc1 | |
The Foreman | =1.2.0-rc2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4180 is classified as a denial of service vulnerability due to excessive memory consumption.
To fix CVE-2013-4180, upgrade Foreman to version 1.2.2 or later.
CVE-2013-4180 affects Foreman versions up to 1.2.1 and specific versions of Red Hat OpenStack 3.0.
The vulnerable actions in CVE-2013-4180 are power and ipmi_boot in the HostController.
Yes, CVE-2013-4180 can be exploited remotely by attackers to cause a denial of service.