CVE-2013-1664
03.04.2013, 00:55
The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack.Enginsight
Vendor | Product | Version |
---|---|---|
openstack | cinder_folsom | - |
openstack | compute_\(nova\)_essex | - |
openstack | compute_\(nova\)_folsom | - |
openstack | folsom | - |
openstack | grizzly | - |
openstack | keystone_essex | - |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
cinder |
| ||||||||||||
keystone |
| ||||||||||||
nova |
|

Ubuntu Releases
Ubuntu Product | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
cinder |
| ||||||||||
keystone |
| ||||||||||
nova |
| ||||||||||
python-django |
| ||||||||||
quantum |
|
Common Weakness Enumeration
References