Summary: | <sys-cluster/neutron-2015.2.9999: Admin-only network attributes may be reset to defaults by non-privileged users (CVE-2014-6414) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Kristian Fiskerstrand (RETIRED) <k_f> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | ||
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://seclists.org/oss-sec/2014/q3/602 | ||
Whiteboard: | ~3 [noglsa] | ||
Package list: | Runtime testing required: | --- |
Description
Kristian Fiskerstrand (RETIRED)
![]() CVE-2014-6414 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-6414): OpenStack Neutron before 2014.2.4 and 2014.1 before 2014.1.2 allows remote authenticated users to set admin network attributes to default values via unspecified vectors. vulnerable versions removed from tree, also, the CVE description is wrong. OpenStack Neutron before 2014.2.4 should be OpenStack Neutron before 2013.2.4 Per previous comments no vulnerable versions in tree. |