PT-2016-3680 · Openstack · Openstack Orchestration Api

Steven Hardy

·

Publicado

2016-01-20

·

Atualizado

2023-02-13

·

CVE-2015-5295

CVSS v2.0

5.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions OpenStack Orchestration API (Heat) versions prior to 2015.1.3 OpenStack Orchestration API (Heat) versions 5.0.x prior to 5.0.1
Description The issue allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files via the resource type in a template. This can be demonstrated by using the file:///dev/zero resource type in a template.
Recommendations For versions prior to 2015.1.3, update to version 2015.1.3 or later. For versions 5.0.x prior to 5.0.1, update to version 5.0.1 or later.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-5295
RHSA-2016:0266
RHSA-2016:0440
RHSA-2016:0441
RHSA-2016:0442

Produtos afetados

Openstack Orchestration Api