PT-2016-3680 · Openstack · Openstack Orchestration Api

Steven Hardy

·

Published

2016-01-20

·

Updated

2023-02-13

·

CVE-2015-5295

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions OpenStack Orchestration API (Heat) versions prior to 2015.1.3 OpenStack Orchestration API (Heat) versions 5.0.x prior to 5.0.1
Description The issue allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files via the resource type in a template. This can be demonstrated by using the file:///dev/zero resource type in a template.
Recommendations For versions prior to 2015.1.3, update to version 2015.1.3 or later. For versions 5.0.x prior to 5.0.1, update to version 5.0.1 or later.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2015-5295
RHSA-2016:0266
RHSA-2016:0440
RHSA-2016:0441
RHSA-2016:0442

Affected Products

Openstack Orchestration Api