CVE-2014-7821
published 2014-11-24CVE-2014-7821: OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (crash) via a crafted…
PriorityP417medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
3.94%
89.2th percentile
OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (crash) via a crafted dns_nameservers value in the DNS configuration.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | neutron | < neutron 2014.1.3-6 (bookworm) | neutron 2014.1.3-6 (bookworm) |
| fedoraproject | fedora | — | — |
| openstack | neutron | >= 0 < 2014.1.3-6 | 2014.1.3-6 |
| openstack | neutron | >= 0 < 2014.1.3-6 | 2014.1.3-6 |
| openstack | neutron | >= 0 < 2014.1.3-6 | 2014.1.3-6 |
| openstack | neutron | >= 0 < 2014.1.3-6 | 2014.1.3-6 |
| openstack | neutron | >= 2012.2.1 < 2014.1.4 | 2014.1.4 |
| openstack | neutron | >= 2014.2 < 2014.2.1 | 2014.2.1 |
| redhat | openstack | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openstack-neutron: DoS via maliciously crafted dns_nameservers
vendor_redhat·2014-11-19·CVSS 4.0
CVE-2014-7821 [MEDIUM] CWE-20 openstack-neutron: DoS via maliciously crafted dns_nameservers
openstack-neutron: DoS via maliciously crafted dns_nameservers
OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (crash) via a crafted dns_nameservers value in the DNS configuration.
A denial of service flaw was found in the way neutron handled the 'dns_nameservers' parameter. By providing specially crafted 'dns_nameservers' values, an authenticated user could use this flaw to crash the neutron service.
Debian
CVE-2014-7821: neutron - OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote aut...
vendor_debian·2014·CVSS 4.0
CVE-2014-7821 [MEDIUM] CVE-2014-7821: neutron - OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote aut...
OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (crash) via a crafted dns_nameservers value in the DNS configuration.
Scope: local
bookworm: resolved (fixed in 2014.1.3-6)
bullseye: resolved (fixed in 2014.1.3-6)
forky: resolved (fixed in 2014.1.3-6)
sid: resolved (fixed in 2014.1.3-6)
trixie: resolved (fixed in 2014.1.3-6)
GHSA
GHSA-3v86-wqpm-qc9x: OpenStack Neutron before 2014
ghsa_unreviewed·2022-05-14
CVE-2014-7821 [MEDIUM] CWE-20 GHSA-3v86-wqpm-qc9x: OpenStack Neutron before 2014
OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (crash) via a crafted dns_nameservers value in the DNS configuration.
OSV
CVE-2014-7821: OpenStack Neutron before 2014
osv·2014-11-24·CVSS 4.0
CVE-2014-7821 [MEDIUM] CVE-2014-7821: OpenStack Neutron before 2014
OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (crash) via a crafted dns_nameservers value in the DNS configuration.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-7821 openstack-neutron: DoS via maliciously crafted dns_nameservers [fedora-all]
bugzilla·2014-11-19·CVSS 4.0
CVE-2014-7821 [MEDIUM] CVE-2014-7821 openstack-neutron: DoS via maliciously crafted dns_nameservers [fedora-all]
CVE-2014-7821 openstack-neutron: DoS via maliciously crafted dns_nameservers [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2014-7821 openstack-neutron: DoS via maliciously crafted dns_nameservers
bugzilla·2014-11-12·CVSS 4.0
CVE-2014-7821 [MEDIUM] CVE-2014-7821 openstack-neutron: DoS via maliciously crafted dns_nameservers
CVE-2014-7821 openstack-neutron: DoS via maliciously crafted dns_nameservers
Reporter: Henry Yamauchi, Charles Neill and Michael Xin (Rackspace)
Products: Neutron
Versions: up to 2014.1.3 and 2014.2
Description:
Henry Yamauchi, Charles Neill and Michael Xin from Rackspace reported a
vulnerability in Neutron. By configuring a maliciously crafted
dns_nameservers an authenticated user may crash Neutron service
resulting in a denial of service attack. All Neutron setups are
affected.
Acknowledgements:
Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges Henry Yamauchi, Charles Neill and Michael Xin (Rackspace) as the original reporters.
Discussion:
Created attachment 956842
patch for CVE-2014-7821 (stable-juno)
---
Created attachment 956843
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155351.htmlhttp://lists.openstack.org/pipermail/openstack-announce/2014-November/000303.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1938.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1942.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0044.htmlhttp://secunia.com/advisories/62586http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttps://bugs.launchpad.net/neutron/+bug/1378450https://exchange.xforce.ibmcloud.com/vulnerabilities/98818http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155351.htmlhttp://lists.openstack.org/pipermail/openstack-announce/2014-November/000303.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1938.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1942.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0044.htmlhttp://secunia.com/advisories/62586http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttps://bugs.launchpad.net/neutron/+bug/1378450https://exchange.xforce.ibmcloud.com/vulnerabilities/98818
2014-11-24
Published