~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2013-4261

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDateAtUSN: 2013-08-22
2
 
Candidate: CVE-2013-4261
3
 
PublicDate: 2013-10-29
4
 
References:
5
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4261
6
 
 https://bugzilla.redhat.com/show_bug.cgi?id=999164
7
 
 https://bugs.launchpad.net/nova/+bug/1215091
8
 
 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4261
9
 
 https://bugs.launchpad.net/nova/+bug/1175808
10
 
 https://usn.ubuntu.com/usn/usn-2000-1
11
 
Description:
12
 
 OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache
13
 
 Qpid for the RPC backend, does not properly handle errors that occur during
14
 
 messaging, which allows remote attackers to cause a denial of service
15
 
 (connection pool consumption), as demonstrated using multiple requests that
16
 
 send long strings to an instance console and retrieving the console log.
17
 
Ubuntu-Description:
18
 
Notes:
19
 
 jdstrand> Ubuntu 13.04 has fix in raring-updates
20
 
 jdstrand> backward-compatibility breaking change deemed too intrusive for
21
 
  stable release update
22
 
Bugs:
23
 
Priority: low
24
 
Discovered-by: Jaroslav Henner
25
 
Assigned-to:
26
 
 
27
 
Patches_nova:
28
 
upstream_nova: released (1:2013.2~rc2)
29
 
lucid_nova: DNE
30
 
precise_nova: ignored
31
 
quantal_nova: ignored
32
 
raring_nova: released (1:2013.1.3-0ubuntu1.1)
33
 
saucy_nova: not-affected (1:2013.2~rc2-0ubuntu1)
34
 
devel_nova: not-affected (1:2013.2~rc2-0ubuntu1)