CVE-2015-5695 Information
Feb 14, 2021
cve
Description
Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain and Records per RecordSet quotas when processing an internal zone file transfer which might allow remote attackers to cause a denial of service (infinite loop) via a crafted resource record set.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Reference
http://lists.openstack.org/pipermail/openstack/2015-July/013548.html http://www.openwall.com/lists/oss-security/2015/07/28/11 http://www.openwall.com/lists/oss-security/2015/07/29/6 https://bugs.launchpad.net/designate/+bug/1471161 https://bugzilla.redhat.com/show_bug.cgi?id=1245241 https://launchpadlibrarian.net/211525251/bug-1471161-quotas-master.patch
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
HIGH
Base Severity
6.5
Share on: