CVE-2016-5363

high
Published 2016-06-17 ยท Modified 2024-11-28
CVSS v3
8.2
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
8.2

Description

The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended MAC-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via (1) a crafted DHCP discovery message or (2) crafted non-IP traffic.

Predictions

Exploit likelihood
88%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker ยท View original โ†— ยท DFSG

CVE-2016-5363 NameCVE-2016-5363 DescriptionThe IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended MAC-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via (1) a crafted DHCP discovery message or (2) crafted non-IP traffic. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec,โ€ฆ

CVE-2016-5363

NameCVE-2016-5363
DescriptionThe IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended MAC-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via (1) a crafted DHCP discovery message or (2) crafted non-IP traffic.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
neutron (PTS)bullseye (security), bullseye2:17.2.1-0+deb11u1fixed
bookworm2:21.0.0-7fixed
trixie2:26.0.0-9fixed
forky2:27.0.1-6fixed
sid2:28.0.0-6fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
neutronsource(unstable)2:8.1.2-1

Notes

[jessie] - neutron <no-dsa> (Minor issue)
https://bugs.launchpad.net/bugs/1558658

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[jessie] - neutron <no-dsa> (Minor issue)https://bugs.launchpad.net/bugs/1558658

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 2:8.1.2-1
sid Fixed 2:8.1.2-1
forky Fixed 2:8.1.2-1
bullseye Fixed 2:8.1.2-1
bookworm Fixed 2:8.1.2-1

Package impact

EcosystemPackageVulnerableFixed
python PyPIneutron<7.1.07.1.0
python PyPIneutron>=8.0.0,<8.1.08.1.0

Application impact

VendorProductVersionsFixed
openstackneutron7.0.0
openstackneutron7.0.1
openstackneutron7.0.2
openstackneutron7.0.3
openstackneutron7.0.4
openstackneutron8.0.0
openstackneutron8.1.0

References

CWEs

CWE-254

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.