Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m6h2-634h-jcpj

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

Designate mDNS DoS through incorrect handling of large RecordSets

Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted resource record set.

Пакеты

Наименование

designate

pip
Затронутые версииВерсия исправления

= 2015.1.0b2

Отсутствует

EPSS

Процентиль: 85%
0.02434
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 8 лет назад

Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted resource record set.

redhat
больше 10 лет назад

Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted resource record set.

CVSS3: 6.5
nvd
больше 8 лет назад

Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted resource record set.

CVSS3: 6.5
debian
больше 8 лет назад

Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo doe ...

EPSS

Процентиль: 85%
0.02434
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-400