The L3-agent in OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to cause a denial of service (IPv4 address attachment outage) by attaching an IPv6 private subnet to a L3 router.
References
Link | Resource |
---|---|
http://seclists.org/oss-sec/2014/q2/572 | Mailing List Third Party Advisory |
http://secunia.com/advisories/59533 | Permissions Required |
http://www.ubuntu.com/usn/USN-2255-1 | Third Party Advisory |
https://bugs.launchpad.net/neutron/+bug/1309195 | Issue Tracking Vendor Advisory |
http://seclists.org/oss-sec/2014/q2/572 | Mailing List Third Party Advisory |
http://secunia.com/advisories/59533 | Permissions Required |
http://www.ubuntu.com/usn/USN-2255-1 | Third Party Advisory |
https://bugs.launchpad.net/neutron/+bug/1309195 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
21 Nov 2024, 02:09
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/oss-sec/2014/q2/572 - Mailing List, Third Party Advisory | |
References | () http://secunia.com/advisories/59533 - Permissions Required | |
References | () http://www.ubuntu.com/usn/USN-2255-1 - Third Party Advisory | |
References | () https://bugs.launchpad.net/neutron/+bug/1309195 - Issue Tracking, Vendor Advisory |
Information
Published : 2014-07-11 14:55
Updated : 2024-11-21 02:09
NVD link : CVE-2014-4167
Mitre link : CVE-2014-4167
CVE.ORG link : CVE-2014-4167
JSON object : View
Products Affected
openstack
- neutron
canonical
- ubuntu_linux
CWE
CWE-264
Permissions, Privileges, and Access Controls