PT-2017-6883 · Openstack · Openstack Designate

Florian Weimer

·

Published

2017-08-31

·

Updated

2022-05-17

·

CVE-2015-5695

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenStack Kilo Designate versions 2015.1.0 through 1.0.0.0b1
Description The issue does not properly enforce RecordSets per domain and Records per RecordSet quotas when processing an internal zone file transfer. This could allow remote attackers to cause a denial of service, potentially resulting in an infinite loop, via a crafted resource record set.
Recommendations For Designate versions 2015.1.0 through 1.0.0.0b1, as a temporary workaround, consider restricting the processing of internal zone file transfers to prevent potential denial of service attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-5695
GHSA-M6H2-634H-JCPJ
PYSEC-2017-114

Affected Products

Openstack Designate