CVE-2016-10149

Related Vulnerabilities: CVE-2016-10149  

An XML entity expansion vulnerability was found in python-pysaml2. A remote attacker could send a crafted request which would cause denial of service through resource exhaustion.

An XML entity expansion vulnerability was found in python-pysaml2. A remote attacker could send a crafted request which would cause denial of service through resource exhaustion.

Find out more about CVE-2016-10149 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

CVSS3 Base Score 5.3
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity Impact None
Availability Impact Low

Red Hat Security Errata

Platform Errata Release Date
Red Hat OpenStack Platform 9.0 (python-pysaml2) RHSA-2017:0937 2017-04-12
Red Hat OpenStack Platform 10 (python-pysaml2) RHSA-2017:0938 2017-04-12
Red Hat OpenStack Platform 8.0 (Liberty) (python-pysaml2) RHSA-2017:0936 2017-04-12

Affected Packages State

Platform Package State
Red Hat OpenStack Platform 11.0 (Ocata) python-pysaml2 Not affected
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 python-pysaml2 Will not fix