|
|
Subscribe / Log in / New account

ganeti: multiple vulnerabilities

Package(s):ganeti CVE #(s):CVE-2015-7944 CVE-2015-7945
Created:January 1, 2016 Updated:January 15, 2016
Description:

From the bug report:

CVE-2015-7945: The distributed replicated storage (DRBD) secret is leaked by the RAPI interface when job results are requested. Leveraging on the knowledge of this secret, a malicious user who had already gained access to the storage network of the cluster can retrieve instance data more easily and reliably.

CVE-2015-7944: The RAPI interface is also vulnerable to a DoS condition, triggered via SSL parameter renegotiation issued by a malicious client. The condition leads to resource exhaustion on the master node.

Alerts:
Debian DSA-3431-2 ganeti 2016-01-14
Debian DSA-3431-1 ganeti 2016-01-01

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds