CVE-2015-5694: Medium severity Openstack Designate vulnerability
Designate does not enforce the DNS protocol limit concerning record set sizes
Other sources
It was discovered that the Designate component in OpenStack would enter an infinite loop when processing an internal zone file transfer if a managed DNS zone included a resource record set whose size exceeded the limitations of the DNS protocol, leading to a denial of service. Only authenticated users with access to the Designate component can add such resource record sets.
Acknowledgements:
This issue was discovered by Florian Weimer of Red Hat Product Security.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5694?
CVE-2015-5694 is classified as a high severity vulnerability due to its potential to cause an infinite loop and denial of service.
How do I fix CVE-2015-5694?
To fix CVE-2015-5694, upgrade Designate to a version that is not affected, such as 1:11.0.0-2, 1:15.0.0-4, or 1:19.0.0-1.
Which versions of Designate are affected by CVE-2015-5694?
Affected versions of Designate include any prior to 1:11.0.0-2, 1:15.0.0-4, and 1:19.0.0-1, as well as 2015.1.0b2.
What impact does CVE-2015-5694 have on OpenStack installations?
CVE-2015-5694 can cause OpenStack's Designate component to enter an infinite loop, leading to service disruption.
Is CVE-2015-5694 relevant for DNS management in OpenStack?
Yes, CVE-2015-5694 directly affects the processing of DNS records in OpenStack's Designate, making it critical for DNS management.