OpenStack Neutron Denial of Service Vulnerability (CVE-2014-3555)
Release date:
Updated on:
Affected Systems:
Openstack Neutron
Description:
--------------------------------------------------------------------------------
Bugtraq id: 68765
CVE (CAN) ID: CVE-2014-3555
OpenStack Neutron is a network-as-a-service project between Interface Devices managed by the Openstack service.
OpenStack Neutron has a Denial-of-Service vulnerability when dealing with allowed address pairs. By creating a large number of allowed address pairs, Authenticated Users can defeat the neutron firewall rules and display that the computing node is unavailable. All neutron settings are affected.
<* Source: Liping Mao
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Openstack
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Juno (development branch) fix:
Https://review.openstack.org/107734
Icehouse fix:
Https://review.openstack.org/107733
Havana fix:
Https://review.openstack.org/107731
Install and deploy Openstack on Ubuntu 12.10
Ubuntu 12.04 OpenStack Swift single-node deployment Manual
OpenStack cloud computing quick start tutorial
Deploying OpenStack for enterprises: what should be done and what should not be done
CentOS 6.5 x64bit quick OpenStack Installation
This article permanently updates the link address: