Vulnerability CVE-2015-5695


Published: 2017-08-31   Modified: 2017-09-01

Description:
Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted resource record set.

CVSS2 => (AV:N/AC:L/Au:S/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4/10
2.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
Openstack -> Designate 

 References:
http://lists.openstack.org/pipermail/openstack/2015-July/013548.html
http://www.openwall.com/lists/oss-security/2015/07/28/11
http://www.openwall.com/lists/oss-security/2015/07/29/6
https://bugs.launchpad.net/designate/+bug/1471161
https://bugzilla.redhat.com/show_bug.cgi?id=1245241
https://launchpadlibrarian.net/211525251/bug-1471161-quotas-master.patch

Copyright 2022, cxsecurity.com

 

Back to Top