Home page logo
/

oss-sec logo oss-sec mailing list archives

[OSSA 2013-026] Potential denial of service on Nova when using Qpid (CVE-2013-4261)
From: Thierry Carrez <thierry () openstack org>
Date: Thu, 12 Sep 2013 17:20:29 +0200

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

OpenStack Security Advisory: 2013-026
CVE: CVE-2013-4261
Date: September 12, 2013
Title: Potential denial of service on Nova when using Qpid
Reporter: Jaroslav Henner (Red Hat)
Products: Nova
Affects: Folsom, Grizzly

Description:
Jaroslav Henner from Red Hat reported a vulnerability in Nova when using
Apache Qpid as the RPC backend. By sending any random text longer than
65K characters to an instance console and requesting the console log
contents through the API, an authenticated user may disrupt the
nova-compute node his instance is running on. This vulnerability could
be leveraged in a Denial of Service attack against the cloud provider.
Only Folsom and Grizzly setups using Qpid as their RPC backend are
affected. Havana setups, or setups using other RPC backends (like
RabbitMQ), are all unaffected.

Grizzly fix:
https://review.openstack.org/#/c/43303/

Folsom fix:
https://review.openstack.org/#/c/45426/

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4261
https://bugs.launchpad.net/nova/+bug/1215091

Regards,

- -- 
Thierry Carrez
OpenStack Vulnerability Management Team
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Using GnuPG with undefined - http://www.enigmail.net/

iQIcBAEBCAAGBQJSMdu9AAoJEFB6+JAlsQQjenQQAJWcaFpLYRVzGarpbDIyFnU6
Pvrg5fBuJhPbrNNr+oSFcrMbIy4G70COfY53GEq1JyZ122Oo3//KpK9QpPxSck8F
aeQa7YqJJocI1XoyVkpOZIMD8lOERZpLZpotV3UuzmKV1KS2W5UAJ3CTvBWcuhZq
YlFmvEz1Hqryrk3nLPtXCQrhG5SnCwFUIu3AXrBNcp5+7dG1kulniz4Bjp1fNdgb
dGFNUGY+YK+by7SuwcuTKgRwes2kB0HPVR/AyfailpUMFljgvjNx6zybaIhOt3CT
eZHLJwxyDJDPZriZZtR23+5M6dZdnd/OZIbZOCZnSvAmq+R4NSCTMU9nJIQFbvdQ
Ar2WgWQgOwjqjjDngOMxnizVHkOx26JE5NIiwhQeucjHA797G8fJ51GQ71nhBEne
kclRCVIn9wLFJSNN6/TqgfF0e44GTtsRxCKlFtHwVPwSI/KBICZKTt3VyY/6njN6
n2UWubbqqYtN05a0VK281ah3RbZYOPLtkZGCuI+PPzwGnNBl9gJk+9o8+jCVEPSY
3Pn43//fOFM5GAoFngescTqzl1W08T7Zii+UsBbYAfCF3ym+TswPY41MYXui2d4j
bqlsh8sOhVfKBHCJNB3UKKTZ2IFBo0ve8JlyAgZfw2GbJ928+CfqVAJ27vwmzT5N
03iM2MHgLDGsCf1D+dcK
=+ZxS
-----END PGP SIGNATURE-----


  By Date           By Thread  

Current thread:
  • [OSSA 2013-026] Potential denial of service on Nova when using Qpid (CVE-2013-4261) Thierry Carrez (Sep 12)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
AlienVault