Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3221

Опубликовано: 23 июн. 2015
Источник: redhat
CVSS2: 4
EPSS Средний

Описание

OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool.

A Denial-of-Service flaw was found in the OpenStack Networking (neutron) L2 agent when using the iptables firewall driver. By submitting an address pair that is rejected as invalid by the ipset tool (with zero prefix size), an authenticated attacker can cause the L2 agent to crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)openstack-neutronNot affected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)openstack-neutronNot affected
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7openstack-neutronFixedRHSA-2015:168024.08.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-248
https://bugzilla.redhat.com/show_bug.cgi?id=1232284openstack-neutron: L2 agent DoS through incorrect allowed address pairs

EPSS

Процентиль: 93%
0.1067
Средний

4 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool.

nvd
больше 10 лет назад

OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool.

debian
больше 10 лет назад

OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 ...

github
больше 3 лет назад

OpenStack Neutron Improper Input Validation vulnerability

suse-cvrf
около 10 лет назад

Security update for openstack-nova and openstack-neutron

EPSS

Процентиль: 93%
0.1067
Средний

4 Medium

CVSS2