Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-1664

Опубликовано: 19 фев. 2013
Источник: redhat
CVSS2: 4.3

Описание

The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack.

Отчет

This issue affects the versions of python as shipped with Red Hat Enterprise Linux 5, 6 and 7. Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5pythonWill not fix
Red Hat Enterprise Linux 6pythonWill not fix
Red Hat Enterprise Linux 7pythonWill not fix
OpenStack Folsom for RHEL 6openstack-keystoneFixedRHSA-2013:059605.03.2013
OpenStack Folsom for RHEL 6openstack-novaFixedRHSA-2013:065721.03.2013
OpenStack Folsom for RHEL 6openstack-cinderFixedRHSA-2013:065821.03.2013
OpenStack Folsom for RHEL 6Django14FixedRHSA-2013:067021.03.2013

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=913808bindings: Internal entity expansion in Python XML libraries inflicts DoS vulnerabilities

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 13 лет назад

The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack.

nvd
больше 13 лет назад

The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack.

debian
больше 13 лет назад

The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used ...

github
больше 4 лет назад

XML Entity Expansion (XEE) in Django

fstec
почти 13 лет назад

Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

4.3 Medium

CVSS2