CVE-2013-1665

NameCVE-2013-1665
DescriptionThe XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex and Folsom, Django, and possibly other products allow remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) attack.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-2634-1
Debian Bugs700948

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
keystone (PTS)buster, buster (security)2:14.2.0-0+deb10u1fixed
bullseye2:18.0.0-3+deb11u1fixed
bookworm2:22.0.0-2fixed
sid2:23.0.0-6fixed
python-django (PTS)buster1:1.11.29-1~deb10u1fixed
buster (security)1:1.11.29-1+deb10u10fixed
bullseye2:2.2.28-1~deb11u1fixed
bullseye (security)2:2.2.28-1~deb11u2fixed
bookworm3:3.2.19-1fixed
bookworm (security)3:3.2.19-1+deb12u1fixed
trixie3:3.2.21-1fixed
sid3:4.2.5-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
keystonesource(unstable)2012.1.1-13700948
python-djangosourcesqueeze1.2.3-3+squeeze5DSA-2634-1
python-djangosource(unstable)1.4.4-1

Search for package or bug name: Reporting problems