CVE-2013-4261

low
Published 2013-10-29 · Modified 2026-04-29
CVSS v3
CVSS v2
3.5
VIR risk
3.5

Description

OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during messaging, which allows remote attackers to cause a denial of service (connection pool consumption), as demonstrated using multiple requests that send long strings to an instance console and retrieving the console log.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-4261

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://bugzilla.redhat.com/show_bug.cgi?id=999164

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://seclists.org/oss-sec/2013/q3/595

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2013-1199.html

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2013.2-1
debian debianbullseyefixed2013.2-1
debian debianforkyfixed2013.2-1
debian debiansidfixed2013.2-1
debian debiantrixiefixed2013.2-1

Application impact

VendorProductVersionsFixed
openstackfolsom{"endIncluding":"-"}
openstackgrizzly{"endIncluding":"-"}
redhatopenstack3.0

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.