cbcvebase.
CVE-2015-5695
published 2017-08-31

CVE-2015-5695: Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an…

PriorityP427medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
2.15%
80.2th percentile
Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted resource record set.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiandesignate< designate 2015.1.0+2015.08.26.git34.9fa07c5798-1 (bookworm)designate 2015.1.0+2015.08.26.git34.9fa07c5798-1 (bookworm)
openstackdesignate
openstackdesignate
openstackdesignate
openstackdesignate>= 0 < 2015.1.0+2015.08.26.git34.9fa07c5798-12015.1.0+2015.08.26.git34.9fa07c5798-1
openstackdesignate>= 0 < 2015.1.0+2015.08.26.git34.9fa07c5798-12015.1.0+2015.08.26.git34.9fa07c5798-1
openstackdesignate>= 0 < 2015.1.0+2015.08.26.git34.9fa07c5798-12015.1.0+2015.08.26.git34.9fa07c5798-1
openstackdesignate>= 0 < 2015.1.0+2015.08.26.git34.9fa07c5798-12015.1.0+2015.08.26.git34.9fa07c5798-1

CVSS provenance

nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.