|
|
| |
|
| |
openstack-keystone: denial of service
| Package(s): | openstack-keystone |
CVE #(s): | CVE-2012-1572
|
| Created: | April 9, 2012 |
Updated: | April 11, 2012 |
| Description: |
From the Red Hat bugzilla:
A vulnerability in how Keystone handles extremely long passwords was
discovered. When Keystone is validating a password, glibc allocated space on the stack for the entire password. If the password is long enough, stack space can be exhausted which will lead to a crash. A remote attacker could use this to cause a crash in Keystone by submitting a long password when attempting to log into an existing account; an attacker must know an existing account name to attempt the login with for this attack to be successful.
|
| Alerts: |
|
( Log in to post comments)
|
|
|