CVE Vulnerabilities

CVE-2016-0738

Published: Jan 29, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
6.8 MODERATE
AV:N/AC:L/Au:S/C:N/I:N/A:C
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.

Affected Software

NameVendorStart VersionEnd Version
SwiftOpenstack*2.3.0 (including)
SwiftOpenstack2.4.0 (including)2.4.0 (including)
SwiftOpenstack2.5.0 (including)2.5.0 (including)
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6RedHatopenstack-swift-0:1.13.1-8.el6ost*
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7RedHatopenstack-swift-0:1.13.1-8.el7ost*
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7RedHatopenstack-swift-0:2.2.0-6.el7ost*
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7RedHatopenstack-swift-0:2.3.0-3.el7ost*
Red Hat Gluster Storage 3.1 for RHEL 6RedHatopenstack-swift-0:1.13.1-8.el6ost*
Red Hat Gluster Storage 3.1 for RHEL 7RedHatopenstack-swift-0:1.13.1-8.el7ost*
SwiftUbuntuprecise*
SwiftUbuntutrusty*
SwiftUbuntuupstream*
SwiftUbuntuvivid*
SwiftUbuntuwily*

References