CVE-2012-1572

unknown
Published — · Modified —
CVSS v3
CVSS v4 NEW
not yet in upstream
VIR risk

Description

OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2012-1572 NameCVE-2012-1572 DescriptionOpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Vulnerable and fixed packages The table below lists information on source packages. Source…

CVE-2012-1572

NameCVE-2012-1572
DescriptionOpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
keystone (PTS)bullseye2:18.0.0-3+deb11u1fixed
bullseye (security)2:18.1.0-1+deb11u3fixed
bookworm, bookworm (security)2:22.0.2-0+deb12u1fixed
trixie (security), trixie2:27.0.0-3+deb13u1fixed
forky2:29.0.1-1fixed
sid2:29.0.1-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
keystonesource(unstable)2012.1~rc2-1

Home - Debian Security - Source (Git)

OS impact

debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 2012.1~rc2-1
sid Fixed 2012.1~rc2-1
forky Fixed 2012.1~rc2-1
bullseye Fixed 2012.1~rc2-1
bookworm Fixed 2012.1~rc2-1

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.