Vulnerability Description
The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13.x before 2.13.3, 2.14.x before 2.14.2, and 2.15.x before 2.15.2, when used in SSL mode, allows remote attackers to cause a denial of service (resource consumption) via SSL parameter renegotiation.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Spi-Inc | Ganeti | <= 2.9.6 |
Related Weaknesses (CWE)
References
- http://docs.ganeti.org/ganeti/2.10/html/news.html#version-2-10-8Release NotesVendor Advisory
- http://docs.ganeti.org/ganeti/2.11/html/news.html#version-2-11-8Release NotesVendor Advisory
- http://docs.ganeti.org/ganeti/2.12/html/news.html#version-2-12.6Release NotesVendor Advisory
- http://docs.ganeti.org/ganeti/2.13/html/news.html#version-2-13-3Release NotesVendor Advisory
- http://docs.ganeti.org/ganeti/2.14/html/news.html#version-2-14-2Release NotesVendor Advisory
- http://docs.ganeti.org/ganeti/2.15/html/news.html#version-2-15-2Release NotesVendor Advisory
- http://docs.ganeti.org/ganeti/2.9/html/news.html#version-2-9-7Release NotesVendor Advisory
- http://packetstormsecurity.com/files/135101/Ganeti-Leaked-Secret-Denial-Of-ServiPatchThird Party AdvisoryVDB Entry
- http://www.debian.org/security/2016/dsa-3431
- http://www.ocert.org/advisories/ocert-2015-012.htmlPatchThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/39169/
- http://docs.ganeti.org/ganeti/2.10/html/news.html#version-2-10-8Release NotesVendor Advisory
- http://docs.ganeti.org/ganeti/2.11/html/news.html#version-2-11-8Release NotesVendor Advisory
- http://docs.ganeti.org/ganeti/2.12/html/news.html#version-2-12.6Release NotesVendor Advisory
- http://docs.ganeti.org/ganeti/2.13/html/news.html#version-2-13-3Release NotesVendor Advisory
FAQ
What is CVE-2015-7944?
CVE-2015-7944 is a vulnerability with a CVSS score of 7.5 (HIGH). The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13.x before 2.13.3, 2.14.x before 2.14.2, and 2.15.x...
How severe is CVE-2015-7944?
CVE-2015-7944 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-7944?
Check the references section above for vendor advisories and patch information. Affected products include: Spi-Inc Ganeti.