Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-5695

Опубликовано: 31 авг. 2017
Источник: nvd
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted resource record set.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openstack:designate:1.0.0.0b1:*:*:*:*:*:*:*
cpe:2.3:a:openstack:designate:1.0.0a0:*:*:*:*:*:*:*
cpe:2.3:a:openstack:designate:2015.1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 85%
0.02434
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 8 лет назад

Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted resource record set.

redhat
больше 10 лет назад

Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted resource record set.

CVSS3: 6.5
debian
больше 8 лет назад

Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo doe ...

CVSS3: 6.5
github
больше 3 лет назад

Designate mDNS DoS through incorrect handling of large RecordSets

EPSS

Процентиль: 85%
0.02434
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-400