Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Cinder could be made to crash if it received specially crafted input.
Software Description:
- cinder: Cinder storage service - api server
Details:
Stuart Stent discovered that Cinder would allow XML entity processing. A
remote unauthenticated attacker could exploit this using the Cinder API to
cause a denial of service via resource exhaustion. (CVE-2013-1664)
The problem can be corrected by updating your system to the following package versions: Ubuntu 12.10: python-cinder 2012.2.1-0ubuntu1.1 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-1731-1
CVE-2013-1664
Get the latest Linux and open source security news straight to your inbox.