MEDIUM
openstack-neutron: DoS via maliciously crafted dns_nameservers
Published Nov 24, 2014
4.0
MEDIUMCVSS 2.0
EPSS 3.94%
Description
OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (crash) via a crafted dns_nameservers value in the DNS configuration.
Affected products
No data.
No data.
OpenStack 4 for RHEL 6
openstack-neutron-0:2013.2.4-6.el6ost
Fixed · RHSA-2015:0044
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6
openstack-neutron-0:2014.1.3-12.el6ost
Fixed · RHSA-2014:1938
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7
openstack-neutron-0:2014.1.3-11.el7ost
Fixed · RHSA-2014:1942
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenStack 4 for RHEL 6 | openstack-neutron-0:2013.2.4-6.el6ost | Fixed | RHSA-2015:0044 |
| Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 | openstack-neutron-0:2014.1.3-12.el6ost | Fixed | RHSA-2014:1938 |
| Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 | openstack-neutron-0:2014.1.3-11.el7ost | Fixed | RHSA-2014:1942 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (13)
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155351.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://lists.openstack.org/pipermail/openstack-announce/2014-November/000303.html mailing-listx_refsource_MLISTPatchVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1938.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1942.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0044.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://secunia.com/advisories/62586 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html x_refsource_CONFIRMThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2014-7821 Vendor Advisory
- https://bugs.launchpad.net/neutron/+bug/1378450 x_refsource_CONFIRMThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1163457 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98818 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://nvd.nist.gov/vuln/detail/CVE-2014-7821
- https://www.cve.org/CVERecord?id=CVE-2014-7821
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 24, 2014
Updated Aug 6, 2024
Reserved Oct 3, 2014
Link CVE-2014-7821
CISA Vulnrichment
Updated n/a