CVE-2013-1665
Publication date 19 February 2013
Last updated 24 July 2024
Ubuntu priority
The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex and Folsom, Django, and possibly other products allow remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) attack.
Status
Package | Ubuntu Release | Status |
---|---|---|
keystone | ||
python-django | ||
Notes
jdstrand
Keystone on 11.10 is a pre-release version and unusable with other components such as nova and horizon
Patch details
Package | Patch details |
---|---|
python-django |
|
References
Related Ubuntu Security Notices (USN)
- USN-1757-1
- Django vulnerabilities
- 7 March 2013
- USN-1730-1
- OpenStack Keystone vulnerabilities
- 20 February 2013