|
|
| |
|
| |
openstack-cinder: multiple vulnerabilities
| Package(s): | openstack-cinder |
CVE #(s): | CVE-2013-4183
CVE-2013-4202
|
| Created: | September 4, 2013 |
Updated: | September 5, 2013 |
| Description: |
From the Red Hat advisory:
It was found that the fixes for CVE-2013-1664 and CVE-2013-1665, released
via RHSA-2013:0658, did not fully correct the issues in the Extensible
Markup Language (XML) parser used by Cinder. A remote attacker could use
this flaw to send a specially-crafted request to a Cinder API, causing
Cinder to consume an excessive amount of CPU and memory, or possibly crash.
(CVE-2013-4202)
A bug in the Cinder LVM driver prevented LVM snapshots from being securely
deleted in some cases, potentially leading to information disclosure to
other tenants. (CVE-2013-4183) |
| Alerts: |
|
( Log in to post comments)
|
|
|