Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: OpenStack: Announce

[OSSA 2013-016] Unchecked user input in Swift XML responses (CVE-2013-2161)

 

 

OpenStack announce RSS feed   Index | Next | Previous | View Threaded


jeremy at openstack

Jun 13, 2013, 9:21 AM

Post #1 of 1 (80 views)
Permalink
[OSSA 2013-016] Unchecked user input in Swift XML responses (CVE-2013-2161)

OpenStack Security Advisory: 2013-016
CVE: CVE-2013-2161
Date: June 13, 2013
Title: Unchecked user input in Swift XML responses
Reporter: Alex Gaynor (Rackspace)
Products: Swift
Affects: All versions

Description:
Alex Gaynor from Rackspace reported a vulnerability in XML handling
within Swift account servers. Account strings were unescaped in XML
listings, and an attacker could potentially generate unparsable or
arbitrary XML responses which may be used to leverage other
vulnerabilities in the calling software.

Havana (development branch) fix:
https://review.openstack.org/32905

Grizzly fix:
https://review.openstack.org/32909

Folsom fix:
https://review.openstack.org/32911

Notes:
This fix will be included in the next release.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2161
https://bugs.launchpad.net/swift/+bug/1183884

--
Jeremy Stanley (fungi)
OpenStack Vulnerability Management Team
Attachments: signature.asc (0.94 KB)

OpenStack announce RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.