PT-2016-3680 · Openstack · Openstack Orchestration Api

·

CVE-2015-5295

·

Published

2016-01-20

·

Updated

2023-02-13

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions OpenStack Orchestration API (Heat) versions prior to 2015.1.3 OpenStack Orchestration API (Heat) versions 5.0.x prior to 5.0.1
Description The issue allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files via the resource type in a template. This can be demonstrated by using the file:///dev/zero resource type in a template.
Recommendations For versions prior to 2015.1.3, update to version 2015.1.3 or later. For versions 5.0.x prior to 5.0.1, update to version 5.0.1 or later.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-5295
RHSA-2016:0266
RHSA-2016:0440
RHSA-2016:0441
RHSA-2016:0442

Affected Products

Openstack Orchestration Api