First published: Mon Nov 24 2014(Updated: )
OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (crash) via a crafted dns_nameservers value in the DNS configuration.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Neutron | >=2012.2.1<2014.1.4 | |
OpenStack Neutron | >=2014.2<2014.2.1 | |
Fedora | =20 | |
Red Hat OpenStack for IBM Power | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-7821 is considered a high severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2014-7821, upgrade OpenStack Neutron to version 2014.1.4 or 2014.2.1 or later.
CVE-2014-7821 affects OpenStack Neutron versions before 2014.1.4 and 2014.2.x before 2014.2.1, along with specific Fedora and Red Hat OpenStack versions.
CVE-2014-7821 can be exploited through a crafted dns_nameservers value in the DNS configuration, leading to a crash.
Yes, CVE-2014-7821 allows remote authenticated users to exploit the vulnerability.