LWN.net Logo

openstack-cinder: multiple vulnerabilities

Package(s):openstack-cinder CVE #(s):CVE-2013-4183 CVE-2013-4202
Created:September 4, 2013 Updated:September 5, 2013
Description: From the Red Hat advisory:

It was found that the fixes for CVE-2013-1664 and CVE-2013-1665, released via RHSA-2013:0658, did not fully correct the issues in the Extensible Markup Language (XML) parser used by Cinder. A remote attacker could use this flaw to send a specially-crafted request to a Cinder API, causing Cinder to consume an excessive amount of CPU and memory, or possibly crash. (CVE-2013-4202)

A bug in the Cinder LVM driver prevented LVM snapshots from being securely deleted in some cases, potentially leading to information disclosure to other tenants. (CVE-2013-4183)

Alerts:
Red Hat RHSA-2013:1198-01 2013-09-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds