CVE-2016-5362: OpenStack Neutron allows remote attackers to bypass an intended DHCP-spoofing protection mechanism
(updated )
The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended DHCP-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via a crafted DHCP discovery message.
References
- access.redhat.com/errata/RHSA-2016:1473
- access.redhat.com/errata/RHSA-2016:1474
- bugs.launchpad.net/neutron/+bug/1558658
- github.com/advisories/GHSA-qpwc-p365-pqrr
- github.com/openstack/neutron
- nvd.nist.gov/vuln/detail/CVE-2016-5362
- review.openstack.org/
- review.openstack.org/
- review.openstack.org/
- security.openstack.org/ossa/OSSA-2016-009.html
Code Behaviors & Features
Detect and mitigate CVE-2016-5362 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →