CVE-2016-0738
published 2016-01-29CVE-2016-0738: OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote…
PriorityP337high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
3.82%
88.9th percentile
OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | swift | < swift 2.5.0-3 (bookworm) | swift 2.5.0-3 (bookworm) |
| openstack | swift | <= 2.3.0 | — |
| openstack | swift | — | — |
| openstack | swift | — | — |
| openstack | swift | >= 0 < 2.5.0-3 | 2.5.0-3 |
| openstack | swift | >= 0 < 2.5.0-3 | 2.5.0-3 |
| openstack | swift | >= 0 < 2.5.0-3 | 2.5.0-3 |
| openstack | swift | >= 0 < 2.5.0-3 | 2.5.0-3 |
| openstack | swift | >= 0 < 2.3.1 | 2.3.1 |
| openstack | swift | >= 0 < 1.13.1-0ubuntu1.5 | 1.13.1-0ubuntu1.5 |
| openstack | swift | >= 2.4.0 < 2.5.1 | 2.5.1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Object Storage (Swift) allows remote attackers to cause a denial of service
ghsa·2022-05-17
CVE-2016-0738 [HIGH] OpenStack Object Storage (Swift) allows remote attackers to cause a denial of service
OpenStack Object Storage (Swift) allows remote attackers to cause a denial of service
OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.
OSV
OpenStack Object Storage (Swift) allows remote attackers to cause a denial of service
osv·2022-05-17
CVE-2016-0738 [HIGH] OpenStack Object Storage (Swift) allows remote attackers to cause a denial of service
OpenStack Object Storage (Swift) allows remote attackers to cause a denial of service
OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.
OSV
swift vulnerabilities
osv·2017-10-11·CVSS 5.0
CVE-2015-5223 [MEDIUM] swift vulnerabilities
swift vulnerabilities
It was discovered that OpenStack Swift incorrectly handled tempurls. A
remote authenticated user in possession of a tempurl key authorized for PUT
could retrieve other objects in the same Swift account. (CVE-2015-5223)
Romain Le Disez and Örjan Persson discovered that OpenStack Swift
incorrectly closed client connections. A remote attacker could possibly use
this issue to consume resources, resulting in a denial of service.
(CVE-2016-0737, CVE-2016-0738)
OSV
CVE-2016-0738: OpenStack Object Storage (Swift) before 2
osv·2016-01-29·CVSS 7.5
CVE-2016-0738 [HIGH] CVE-2016-0738: OpenStack Object Storage (Swift) before 2
OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.
Ubuntu
OpenStack Swift vulnerabilities
vendor_ubuntu·2017-10-11·CVSS 5.0
CVE-2015-5223 [MEDIUM] OpenStack Swift vulnerabilities
Title: OpenStack Swift vulnerabilities
Summary: Several security issues were fixed in OpenStack Swift.
It was discovered that OpenStack Swift incorrectly handled tempurls. A
remote authenticated user in possession of a tempurl key authorized for PUT
could retrieve other objects in the same Swift account. (CVE-2015-5223)
Romain Le Disez and Örjan Persson discovered that OpenStack Swift
incorrectly closed client connections. A remote attacker could possibly use
this issue to consume resources, resulting in a denial of service.
(CVE-2016-0737, CVE-2016-0738)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openstack-swift: Proxy to server DoS through Large Objects
vendor_redhat·2016-01-20·CVSS 7.5
CVE-2016-0738 [HIGH] CWE-400 openstack-swift: Proxy to server DoS through Large Objects
openstack-swift: Proxy to server DoS through Large Objects
OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.
A memory-leak issue was found in OpenStack Object Storage (swift), in the proxy-to-server connection. An OpenStack-authenticated attacker could remotely trigger this flaw to cause denial of service through excess memory consumption.
Package: openstack-swift (Red Hat OpenStack Platform 8 (Liberty)) - Not affected
Debian
CVE-2016-0738: swift - OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2....
vendor_debian·2016·CVSS 7.5
CVE-2016-0738 [HIGH] CVE-2016-0738: swift - OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2....
OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.
Scope: local
bookworm: resolved (fixed in 2.5.0-3)
bullseye: resolved (fixed in 2.5.0-3)
forky: resolved (fixed in 2.5.0-3)
sid: resolved (fixed in 2.5.0-3)
trixie: resolved (fixed in 2.5.0-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-0738 openstack-swift: Proxy to server DoS through Large Objects [fedora-all]
bugzilla·2016-01-21·CVSS 7.5
CVE-2016-0738 [HIGH] CVE-2016-0738 openstack-swift: Proxy to server DoS through Large Objects [fedora-all]
CVE-2016-0738 openstack-swift: Proxy to server DoS through Large Objects [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported vers
Bugzilla
CVE-2016-0737 openstack-swift: Client to proxy DoS through Large Objects
bugzilla·2016-01-15·CVSS 7.5
CVE-2016-0737 [HIGH] CVE-2016-0737 openstack-swift: Client to proxy DoS through Large Objects
CVE-2016-0737 openstack-swift: Client to proxy DoS through Large Objects
A DoS vulnerability in openstack-swift was reported. By repeatedly requesting and interrupting connections to a Large Object (Dynamic or Static) URL, a remote attacker may exhausts Swift proxy-server resources, potentially resulting in a denial of service.
Affects versions: >=2.2.1 <= 2.3.0
Upstream patch:
https://review.openstack.org/#/c/217750/
There are similar bugs CVE-2016-0737 and CVE-2016-0738. This (CVE-2016-0737) is for client to proxy connection.
Discussion:
Created openstack-swift tracking bugs for this issue:
Affects: fedora-all [bug 1300608]
---
This issue is now public.
---
This issue has been addressed in the following products:
OpenStack 6 for RHEL 7
Via RHSA-2016:0128 https://rhn.redhat.
Bugzilla
CVE-2016-0738 openstack-swift: Proxy to server DoS through Large Objects
bugzilla·2016-01-15·CVSS 7.5
CVE-2016-0738 [HIGH] CVE-2016-0738 openstack-swift: Proxy to server DoS through Large Objects
CVE-2016-0738 openstack-swift: Proxy to server DoS through Large Objects
A DoS vulnerability in openstack-swift was reported. By repeatedly requesting and interrupting connections to a Large Object (Dynamic or Static) URL, a remote attacker may exhausts Swift proxy-server resources, potentially resulting in a denial of service.
Affects versions: >=2.2.1 = 2.4.0 <= 2.5.0
There are two similar bugs, CVE-2016-0738 is for proxy to server connection.
Discussion:
Created attachment 1115108
Master/mitaka patch
---
Created attachment 1115109
Stable/kilo patch
---
Created attachment 1115112
Stable/liberty patch
---
Created openstack-swift tracking bugs for this issue:
Affects: fedora-all [bug 1300613]
---
This issue is now public.
---
openstack-swift-2.3.0-3.fc23 has been pushed to
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176713.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0128.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0155.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0329.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/81432https://bugs.launchpad.net/cloud-archive/+bug/1493303https://github.com/openstack/swift/blob/master/CHANGELOGhttps://security.openstack.org/ossa/OSSA-2016-004.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/176713.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0128.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0155.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0329.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/81432https://bugs.launchpad.net/cloud-archive/+bug/1493303https://github.com/openstack/swift/blob/master/CHANGELOGhttps://security.openstack.org/ossa/OSSA-2016-004.html
2016-01-29
Published