CVE-2014-7821

OpenStack Neutron 2012.2.1-2014.1.4 - Authenticated Denial of Service via DNS Configuration

Title source: llm
STIX 2.1

Description

OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (crash) via a crafted dns_nameservers value in the DNS configuration.

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/98818
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0044.html
Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155351.html
Patch, Vendor Advisory mailing-list x_refsource_mlist
http://lists.openstack.org/pipermail/openstack-announce/2014-November/000303.html
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-1942.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/62586
Third Party Advisory x_refsource_confirm
https://bugs.launchpad.net/neutron/+bug/1378450
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-1938.html

Scores

EPSS 0.0217
EPSS Percentile 84.5%

Details

CWE
CWE-20 CWE-399
Status published
Products (3)
fedoraproject/fedora 20
openstack/neutron 2012.2.1 - 2014.1.4
redhat/openstack 4.0
Published Nov 24, 2014
Tracked Since Feb 18, 2026