LWN.net Logo

openstack-keystone: denial of service

Package(s):openstack-keystone CVE #(s):CVE-2012-1572
Created:April 9, 2012 Updated:April 11, 2012
Description: From the Red Hat bugzilla:

A vulnerability in how Keystone handles extremely long passwords was discovered. When Keystone is validating a password, glibc allocated space on the stack for the entire password. If the password is long enough, stack space can be exhausted which will lead to a crash. A remote attacker could use this to cause a crash in Keystone by submitting a long password when attempting to log into an existing account; an attacker must know an existing account name to attempt the login with for this attack to be successful.

Alerts:
Fedora FEDORA-2012-4960 2012-04-08

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds