CVE-2015-5695
medium
CVSS v3
6.5
CVSS v2
4.0
VIR risk
6.5
Description
Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted resource record set.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-5695
Vendor advisory: cve@mitre.org — https://launchpadlibrarian.net/211525251/bug-1471161-quotas-master.patch
Vendor advisory: cve@mitre.org — http://lists.openstack.org/pipermail/openstack/2015-July/013548.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 2015.1.0+2015.08.26.git34.9fa07c5798-1 |
| debian | bullseye | fixed | 2015.1.0+2015.08.26.git34.9fa07c5798-1 |
| debian | forky | fixed | 2015.1.0+2015.08.26.git34.9fa07c5798-1 |
| debian | sid | fixed | 2015.1.0+2015.08.26.git34.9fa07c5798-1 |
| debian | trixie | fixed | 2015.1.0+2015.08.26.git34.9fa07c5798-1 |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| PyPI | designate | | |
References
- http://lists.openstack.org/pipermail/openstack/2015-July/013548.html
- http://www.openwall.com/lists/oss-security/2015/07/28/11
- http://www.openwall.com/lists/oss-security/2015/07/29/6
- https://bugs.launchpad.net/designate/+bug/1471161
- https://bugzilla.redhat.com/show_bug.cgi?id=1245241
- https://launchpadlibrarian.net/211525251/bug-1471161-quotas-master.patch
- https://nvd.nist.gov/vuln/detail/CVE-2015-5695
- https://github.com/ironsource-mobile/designate
- https://github.com/pypa/advisory-database/tree/main/vulns/designate/PYSEC-2017-114.yaml
- https://www.openwall.com/lists/oss-security/2015/07/28/11
- https://www.openwall.com/lists/oss-security/2015/07/29/6
- https://security-tracker.debian.org/tracker/CVE-2015-5695
CWEs
CWE-400
Verify integrity in audit chain (admin only). AS-IS.