LWN.net Logo

swift: denial of service

Package(s):swift CVE #(s):CVE-2013-4155
Created:August 13, 2013 Updated:September 4, 2013
Description: From the Debian advisory:

Peter Portante from Red Hat reported a vulnerability in Swift. By issuing requests with an old X-Timestamp value, an authenticated attacker can fill an object server with superfluous object tombstones, which may significantly slow down subsequent requests to that object server, facilitating a Denial of Service attack against Swift clusters.

Alerts:
Debian DSA-2737-1 2013-08-12
Fedora FEDORA-2013-14477 2013-08-18
Red Hat RHSA-2013:1197-01 2013-09-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds