CVE Vulnerabilities

CVE-2015-7944

Published: Aug 18, 2017 | Modified: Sep 08, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13.x before 2.13.3, 2.14.x before 2.14.2, and 2.15.x before 2.15.2, when used in SSL mode, allows remote attackers to cause a denial of service (resource consumption) via SSL parameter renegotiation.

Affected Software

Name Vendor Start Version End Version
Ganeti Spi-inc * 2.9.6 (including)
Ganeti Spi-inc 2.10.0 (including) 2.10.0 (including)
Ganeti Spi-inc 2.10.0-beta1 (including) 2.10.0-beta1 (including)
Ganeti Spi-inc 2.10.0-rc1 (including) 2.10.0-rc1 (including)
Ganeti Spi-inc 2.10.0-rc2 (including) 2.10.0-rc2 (including)
Ganeti Spi-inc 2.10.0-rc3 (including) 2.10.0-rc3 (including)
Ganeti Spi-inc 2.10.1 (including) 2.10.1 (including)
Ganeti Spi-inc 2.10.2 (including) 2.10.2 (including)
Ganeti Spi-inc 2.10.3 (including) 2.10.3 (including)
Ganeti Spi-inc 2.10.4 (including) 2.10.4 (including)
Ganeti Spi-inc 2.10.5 (including) 2.10.5 (including)
Ganeti Spi-inc 2.10.6 (including) 2.10.6 (including)
Ganeti Spi-inc 2.10.7 (including) 2.10.7 (including)
Ganeti Spi-inc 2.11.0 (including) 2.11.0 (including)
Ganeti Spi-inc 2.11.0-beta1 (including) 2.11.0-beta1 (including)
Ganeti Spi-inc 2.11.0-rc1 (including) 2.11.0-rc1 (including)
Ganeti Spi-inc 2.11.1 (including) 2.11.1 (including)
Ganeti Spi-inc 2.11.2 (including) 2.11.2 (including)
Ganeti Spi-inc 2.11.3 (including) 2.11.3 (including)
Ganeti Spi-inc 2.11.4 (including) 2.11.4 (including)
Ganeti Spi-inc 2.11.5 (including) 2.11.5 (including)
Ganeti Spi-inc 2.11.6 (including) 2.11.6 (including)
Ganeti Spi-inc 2.11.7 (including) 2.11.7 (including)
Ganeti Spi-inc 2.12.0 (including) 2.12.0 (including)
Ganeti Spi-inc 2.12.0-beta1 (including) 2.12.0-beta1 (including)
Ganeti Spi-inc 2.12.0-rc1 (including) 2.12.0-rc1 (including)
Ganeti Spi-inc 2.12.0-rc2 (including) 2.12.0-rc2 (including)
Ganeti Spi-inc 2.12.1 (including) 2.12.1 (including)
Ganeti Spi-inc 2.12.2 (including) 2.12.2 (including)
Ganeti Spi-inc 2.12.3 (including) 2.12.3 (including)
Ganeti Spi-inc 2.12.4 (including) 2.12.4 (including)
Ganeti Spi-inc 2.12.5 (including) 2.12.5 (including)
Ganeti Spi-inc 2.13.0 (including) 2.13.0 (including)
Ganeti Spi-inc 2.13.0-beta1 (including) 2.13.0-beta1 (including)
Ganeti Spi-inc 2.13.0-rc1 (including) 2.13.0-rc1 (including)
Ganeti Spi-inc 2.13.1 (including) 2.13.1 (including)
Ganeti Spi-inc 2.13.2 (including) 2.13.2 (including)
Ganeti Spi-inc 2.14.0 (including) 2.14.0 (including)
Ganeti Spi-inc 2.14.0-beta1 (including) 2.14.0-beta1 (including)
Ganeti Spi-inc 2.14.0-beta2 (including) 2.14.0-beta2 (including)
Ganeti Spi-inc 2.14.0-rc1 (including) 2.14.0-rc1 (including)
Ganeti Spi-inc 2.14.0-rc2 (including) 2.14.0-rc2 (including)
Ganeti Spi-inc 2.14.1 (including) 2.14.1 (including)
Ganeti Spi-inc 2.15.0 (including) 2.15.0 (including)
Ganeti Spi-inc 2.15.0-beta1 (including) 2.15.0-beta1 (including)
Ganeti Spi-inc 2.15.0-rc1 (including) 2.15.0-rc1 (including)
Ganeti Spi-inc 2.15.1 (including) 2.15.1 (including)
Ganeti Ubuntu precise *
Ganeti Ubuntu trusty *
Ganeti Ubuntu upstream *
Ganeti Ubuntu vivid *
Ganeti Ubuntu wily *

References