CVE-2013-4261

Source
https://nvd.nist.gov/vuln/detail/CVE-2013-4261
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2013-4261.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2013-4261
Published
2013-10-29T22:55:02Z
Modified
2025-04-11T00:51:21Z
Downstream
Summary
[none]
Details

OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during messaging, which allows remote attackers to cause a denial of service (connection pool consumption), as demonstrated using multiple requests that send long strings to an instance console and retrieving the console log.

References

Affected packages

Debian:11 / nova

Package

Name
nova
Purl
pkg:deb/debian/nova?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2013.2-1

Ecosystem specific

{
    "urgency": "low"
}

Debian:12 / nova

Package

Name
nova
Purl
pkg:deb/debian/nova?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2013.2-1

Ecosystem specific

{
    "urgency": "low"
}

Debian:13 / nova

Package

Name
nova
Purl
pkg:deb/debian/nova?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2013.2-1

Ecosystem specific

{
    "urgency": "low"
}