CVE-2015-5695
published 2017-08-31CVE-2015-5695: Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an…
PriorityP427medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
2.15%
80.2th percentile
Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted resource record set.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | designate | < designate 2015.1.0+2015.08.26.git34.9fa07c5798-1 (bookworm) | designate 2015.1.0+2015.08.26.git34.9fa07c5798-1 (bookworm) |
| openstack | designate | — | — |
| openstack | designate | — | — |
| openstack | designate | — | — |
| openstack | designate | >= 0 < 2015.1.0+2015.08.26.git34.9fa07c5798-1 | 2015.1.0+2015.08.26.git34.9fa07c5798-1 |
| openstack | designate | >= 0 < 2015.1.0+2015.08.26.git34.9fa07c5798-1 | 2015.1.0+2015.08.26.git34.9fa07c5798-1 |
| openstack | designate | >= 0 < 2015.1.0+2015.08.26.git34.9fa07c5798-1 | 2015.1.0+2015.08.26.git34.9fa07c5798-1 |
| openstack | designate | >= 0 < 2015.1.0+2015.08.26.git34.9fa07c5798-1 | 2015.1.0+2015.08.26.git34.9fa07c5798-1 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Designate mDNS DoS through incorrect handling of large RecordSets
osv·2022-05-17
CVE-2015-5695 [HIGH] Designate mDNS DoS through incorrect handling of large RecordSets
Designate mDNS DoS through incorrect handling of large RecordSets
Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted resource record set.
GHSA
Designate mDNS DoS through incorrect handling of large RecordSets
ghsa·2022-05-17
CVE-2015-5695 [HIGH] CWE-400 Designate mDNS DoS through incorrect handling of large RecordSets
Designate mDNS DoS through incorrect handling of large RecordSets
Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted resource record set.
OSV
CVE-2015-5695: Designate 2015
osv·2017-08-31·CVSS 6.5
CVE-2015-5695 [MEDIUM] CVE-2015-5695: Designate 2015
Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted resource record set.
Red Hat
openstack-designate: Infinite loop with large resource record sets
vendor_redhat·2015-07-28·CVSS 6.5
CVE-2015-5695 [MEDIUM] CWE-835 openstack-designate: Infinite loop with large resource record sets
openstack-designate: Infinite loop with large resource record sets
Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted resource record set.
Package: openstack-designate (Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)) - Will not fix
Debian
CVE-2015-5695: designate - Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enfo...
vendor_debian·2015·CVSS 6.5
CVE-2015-5695 [MEDIUM] CVE-2015-5695: designate - Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enfo...
Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted resource record set.
Scope: local
bookworm: resolved (fixed in 2015.1.0+2015.08.26.git34.9fa07c5798-1)
bullseye: resolved (fixed in 2015.1.0+2015.08.26.git34.9fa07c5798-1)
forky: resolved (fixed in 2015.1.0+2015.08.26.git34.9fa07c5798-1)
sid: resolved (fixed in 2015.1.0+2015.08.26.git34.9fa07c5798-1)
trixie: resolved (fixed in 2015.1.0+2015.08.26.git34.9fa07c5798-1)
No detection rules found.
No public exploits indexed.
http://lists.openstack.org/pipermail/openstack/2015-July/013548.htmlhttp://www.openwall.com/lists/oss-security/2015/07/28/11http://www.openwall.com/lists/oss-security/2015/07/29/6https://bugs.launchpad.net/designate/+bug/1471161https://bugzilla.redhat.com/show_bug.cgi?id=1245241https://launchpadlibrarian.net/211525251/bug-1471161-quotas-master.patchhttp://lists.openstack.org/pipermail/openstack/2015-July/013548.htmlhttp://www.openwall.com/lists/oss-security/2015/07/28/11http://www.openwall.com/lists/oss-security/2015/07/29/6https://bugs.launchpad.net/designate/+bug/1471161https://bugzilla.redhat.com/show_bug.cgi?id=1245241https://launchpadlibrarian.net/211525251/bug-1471161-quotas-master.patch
2017-08-31
Published