First published: Fri Jul 11 2014(Updated: )
The L3-agent in OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to cause a denial of service (IPv4 address attachment outage) by attaching an IPv6 private subnet to a L3 router.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Neutron | >=2011.1<=2013.2.3 | |
OpenStack Neutron | =2014.1 | |
OpenStack Neutron | =2014.1.1 | |
Ubuntu Linux | =13.10 | |
Ubuntu Linux | =14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4167 has a medium severity rating as it allows denial of service through a misconfiguration.
To fix CVE-2014-4167, upgrade OpenStack Neutron to version 2013.2.4, 2014.1.2, or later.
CVE-2014-4167 affects users of OpenStack Neutron versions prior to 2013.2.4 and 2014.x before 2014.1.2.
CVE-2014-4167 is classified as a denial of service vulnerability.
Yes, CVE-2014-4167 can be exploited by remote authenticated users to cause service disruption.