CVE-2015-5695
Summary
| CVE | CVE-2015-5695 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-08-31 22:29:00 UTC |
| Updated | 2017-09-12 18:55:00 UTC |
| Description | Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted resource record set. |
Risk And Classification
Problem Types: CWE-400
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Openstack | Designate | 1.0.0.0b1 | All | All | All |
| Application | Openstack | Designate | 1.0.0a0 | All | All | All |
| Application | Openstack | Designate | 2015.1.0 | All | All | All |
| Application | Openstack | Designate | 1.0.0.0b1 | All | All | All |
| Application | Openstack | Designate | 1.0.0a0 | All | All | All |
| Application | Openstack | Designate | 2015.1.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - Re: Re: CVE Request - OpenStack Designate mDNS DoS through incorrect handling of large RecordSets | MLIST | www.openwall.com | Mailing List, Third Party Advisory |
| Bug #1471161 “Designate mDNS DoS through incorrect handling of l...” : Bugs : Designate | CONFIRM | bugs.launchpad.net | Exploit, Issue Tracking, Third Party Advisory |
| 1245241 – (CVE-2015-5694, CVE-2015-5695) CVE-2015-5695 openstack-designate: Infinite loop with large resource record sets | CONFIRM | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| oss-security - Re: CVE Request - OpenStack Designate mDNS DoS through incorrect handling of large RecordSets | MLIST | www.openwall.com | Mailing List, Third Party Advisory |
| launchpadlibrarian.net/211525251/bug-1471161-quotas-master.patch | CONFIRM | launchpadlibrarian.net | Mailing List, Patch, Third Party Advisory |
| OpenStack Open Source Cloud Computing Software » Message: [Openstack] [Security][LP# 1471161] Designate mDNS DoS through incorrect handling of large RecordSets | MLIST | lists.openstack.org | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.