OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/75368 | vdb entry third party advisory |
http://lists.openstack.org/pipermail/openstack-announce/2015-June/000377.html | mailing list vendor advisory |
https://bugs.launchpad.net/neutron/+bug/1461054 | third party advisory |
http://rhn.redhat.com/errata/RHSA-2015-1680.html | vendor advisory |