[PKG-Openstack-devel] Bug#789713: Bug#789713: neutron: CVE-2015-3221: L2 agent DoS through incorrect allowed address pairs

Thomas Goirand zigo at debian.org
Wed Jun 24 08:26:28 UTC 2015


On 06/23/2015 08:22 PM, Salvatore Bonaccorso wrote:
> Source: neutron
> Version: 2015.1.0-1
> Severity: important
> Tags: security upstream fixed-upstream
> 
> Hi,
> 
> the following vulnerability was published for neutron.
> 
> CVE-2015-3221[0]:
> Neutron L2 agent DoS through incorrect allowed address pairs
> 
> If you fix the vulnerability please also make sure to include the
> CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
> 
> For further information see:
> 
> [0] https://security-tracker.debian.org/tracker/CVE-2015-3221
> [1] http://www.openwall.com/lists/oss-security/2015/06/23/3
> 
> Regards,
> Salvatore

Hi,

I have prepared an update for Neutron in Jessie over here:
http://sid.gplhost.com/jessie-proposed-updates/neutron/

the debdiff is there too.

Is it in good shape for uploading?

Cheers,

Thomas Goirand (zigo)



More information about the Openstack-devel mailing list