The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended MAC-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via (1) a crafted DHCP discovery message or (2) crafted non-IP traffic.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Neutron | Openstack | 7.0.0 (including) | 7.0.0 (including) |
Neutron | Openstack | 7.0.1 (including) | 7.0.1 (including) |
Neutron | Openstack | 7.0.2 (including) | 7.0.2 (including) |
Neutron | Openstack | 7.0.3 (including) | 7.0.3 (including) |
Neutron | Openstack | 7.0.4 (including) | 7.0.4 (including) |
Neutron | Openstack | 8.0.0 (including) | 8.0.0 (including) |
Neutron | Openstack | 8.1.0 (including) | 8.1.0 (including) |
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 | RedHat | openstack-neutron-0:2015.1.4-2.el7ost | * |
Red Hat OpenStack Platform 8.0 (Liberty) | RedHat | openstack-neutron-1:7.0.4-11.el7ost | * |
Neutron | Ubuntu | trusty | * |
Neutron | Ubuntu | wily | * |
Neutron | Ubuntu | yakkety | * |