PT-2016-3680 · Openstack · Openstack Orchestration Api
Steven Hardy
·
Published
2016-01-20
·
Updated
2023-02-13
·
CVE-2015-5295
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
OpenStack Orchestration API (Heat) versions prior to 2015.1.3
OpenStack Orchestration API (Heat) versions 5.0.x prior to 5.0.1
Description
The issue allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files via the resource type in a template. This can be demonstrated by using the
file:///dev/zero resource type in a template.Recommendations
For versions prior to 2015.1.3, update to version 2015.1.3 or later.
For versions 5.0.x prior to 5.0.1, update to version 5.0.1 or later.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openstack Orchestration Api