The L3-agent in OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to cause a denial of service (IPv4 address attachment outage) by attaching an IPv6 private subnet to a L3 router.
References
Link | Resource |
---|---|
http://secunia.com/advisories/59533 | Permissions Required |
http://seclists.org/oss-sec/2014/q2/572 | Mailing List Third Party Advisory |
http://www.ubuntu.com/usn/USN-2255-1 | Third Party Advisory |
https://bugs.launchpad.net/neutron/+bug/1309195 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2014-07-11 07:55
Updated : 2018-10-22 10:07
NVD link : CVE-2014-4167
Mitre link : CVE-2014-4167
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
canonical
- ubuntu_linux
openstack
- neutron