漏洞信息详情
OpenStack Neutron 安全漏洞
漏洞简介
OpenStack是美国国家航空航天局(National Aeronautics and Space Administration)和美国Rackspace公司合作研发的一个云平台管理项目。
OpenStack Neutron 存在安全漏洞,该漏洞源于软件中对于extra_dhcp_opts的值缺乏有效的验证和过滤,攻击者通过提供特制的值可以对dnsmasq进程进行任意配置
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://review.opendev.org/c/openstack/neutron/+/806750/
参考网址
来源:DEBIAN
链接:https://www.debian.org/security/2021/dsa-4983
来源:MISC
链接:https://launchpad.net/bugs/1939733
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2021/10/msg00005.html
来源:MLIST
链接:http://www.openwall.com/lists/oss-security/2021/08/31/2
来源:MISC
链接:https://security.openstack.org/ossa/OSSA-2021-005.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3365
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164103/Red-Hat-Security-Advisory-2021-3481-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3067
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3116
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3358
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021101209
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3049
来源:access.redhat.com
链接:https://access.redhat.com/security/cve/cve-2021-40085
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164147/Red-Hat-Security-Advisory-2021-3503-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164166/Red-Hat-Security-Advisory-2021-3488-01.html
受影响实体
暂无
补丁
- OpenStack Neutron 安全漏洞的修复措施<!--2021-8-31-->
还没有评论,来说两句吧...