CVE-2013-4180: Input Validation
Published Sep 16, 2013
·Updated
The (1) power and (2) ipmiboot actions in the HostController in Foreman before 1.2.2 allow remote attackers to cause a denial of service (memory consumption) via unspecified input that is converted to a symbol.
Affected Software
5 affected components
redhat Openstack=3.0
theforeman foreman<=1.2.1
theforeman foreman=1.2.0
theforeman foreman=1.2.0-rc1
theforeman foreman=1.2.0-rc2
Remediation
Event History
Sep 16, 2013
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4180?
CVE-2013-4180 is classified as a denial of service vulnerability due to excessive memory consumption.
2
How do I fix CVE-2013-4180?
To fix CVE-2013-4180, upgrade Foreman to version 1.2.2 or later.
3
What software is affected by CVE-2013-4180?
CVE-2013-4180 affects Foreman versions up to 1.2.1 and specific versions of Red Hat OpenStack 3.0.
4
What actions are vulnerable in CVE-2013-4180?
The vulnerable actions in CVE-2013-4180 are power and ipmi_boot in the HostController.
5
Can CVE-2013-4180 be exploited remotely?
Yes, CVE-2013-4180 can be exploited remotely by attackers to cause a denial of service.