CVE-2014-7821: Input Validation
Published Nov 24, 2014
·Updated
OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (crash) via a crafted dnsnameservers value in the DNS configuration.
Affected Software
4 affected components
Openstack Neutron>=2012.2.1<2014.1.4
Openstack Neutron>=2014.2<2014.2.1
Fedoraproject Fedora=20
redhat Openstack=4.0
Remediation
Event History
Nov 24, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-7821?
CVE-2014-7821 is considered a high severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2014-7821?
To fix CVE-2014-7821, upgrade OpenStack Neutron to version 2014.1.4 or 2014.2.1 or later.
3
Who is affected by CVE-2014-7821?
CVE-2014-7821 affects OpenStack Neutron versions before 2014.1.4 and 2014.2.x before 2014.2.1, along with specific Fedora and Red Hat OpenStack versions.
4
What type of attack can exploit CVE-2014-7821?
CVE-2014-7821 can be exploited through a crafted dns_nameservers value in the DNS configuration, leading to a crash.
5
Can CVE-2014-7821 be exploited remotely?
Yes, CVE-2014-7821 allows remote authenticated users to exploit the vulnerability.