CVE-2014-7821: DoS through invalid DNS configuration

Related Vulnerabilities: CVE-2014-7821  

Debian Bug report logs - #770431
CVE-2014-7821: DoS through invalid DNS configuration

version graph

Reported by: Thomas Goirand <zigo@debian.org>

Date: Fri, 21 Nov 2014 08:21:07 UTC

Severity: important

Tags: patch, security

Found in version 2014.1.3-5

Fixed in versions neutron/2014.1.3-6, neutron/2014.2-4

Done: Thomas Goirand <zigo@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, PKG OpenStack <openstack-devel@lists.alioth.debian.org>:
Bug#770431; Package neutron. (Fri, 21 Nov 2014 08:21:11 GMT) (full text, mbox, link).


Acknowledgement sent to Thomas Goirand <zigo@debian.org>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, secure-testing-team@lists.alioth.debian.org, PKG OpenStack <openstack-devel@lists.alioth.debian.org>. (Fri, 21 Nov 2014 08:21:11 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Thomas Goirand <zigo@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: CVE-2014-7821: DoS through invalid DNS configuration
Date: Fri, 21 Nov 2014 16:19:25 +0800
Package: neutron
Version: 2014.1.3-5
Severity: important
Tags: security patch

OpenStack Security Advisory: 2014-039
CVE: CVE-2014-7821
Date: November 19, 2014
Title: Neutron DoS through invalid DNS configuration
Reporter: Henry Yamauchi, Charles Neill and Michael Xin (Rackspace)
Products: Neutron
Versions: up to 2014.1.3 and 2014.2

Description:
Henry Yamauchi, Charles Neill and Michael Xin from Rackspace reported
a vulnerability in Neutron. By configuring a maliciously crafted
dns_nameservers an authenticated user may crash Neutron service
resulting in a denial of service attack. All Neutron setups are affected.

Kilo (development branch) fix:
https://review.openstack.org/135616

Juno fix:
https://review.openstack.org/135623

Icehouse fix:
https://review.openstack.org/135624

Notes:
This fix will be included in future 2014.1.4 and 2014.2.1 releases.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7821
https://launchpad.net/bugs/1378450



Reply sent to Thomas Goirand <zigo@debian.org>:
You have taken responsibility. (Fri, 21 Nov 2014 09:21:29 GMT) (full text, mbox, link).


Notification sent to Thomas Goirand <zigo@debian.org>:
Bug acknowledged by developer. (Fri, 21 Nov 2014 09:21:30 GMT) (full text, mbox, link).


Message #10 received at 770431-close@bugs.debian.org (full text, mbox, reply):

From: Thomas Goirand <zigo@debian.org>
To: 770431-close@bugs.debian.org
Subject: Bug#770431: fixed in neutron 2014.1.3-6
Date: Fri, 21 Nov 2014 09:20:54 +0000
Source: neutron
Source-Version: 2014.1.3-6

We believe that the bug you reported is fixed in the latest version of
neutron, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 770431@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated neutron package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Fri, 21 Nov 2014 16:25:18 +0800
Source: neutron
Binary: python-neutron neutron-server neutron-common neutron-plugin-nec-agent neutron-l3-agent neutron-dhcp-agent neutron-metadata-agent neutron-metering-agent neutron-vpn-agent neutron-lbaas-agent neutron-plugin-openvswitch-agent neutron-plugin-linuxbridge-agent python-quantum quantum-server quantum-common quantum-plugin-cisco quantum-plugin-nec quantum-plugin-nec-agent quantum-plugin-bigswitch quantum-plugin-hyperv quantum-plugin-brocade quantum-plugin-plumgrid quantum-plugin-metaplugin quantum-plugin-nicira quantum-l3-agent quantum-dhcp-agent quantum-metadata-agent quantum-lbaas-agent quantum-plugin-openvswitch quantum-plugin-openvswitch-agent quantum-plugin-linuxbridge quantum-plugin-linuxbridge-agent
Architecture: source all
Version: 2014.1.3-6
Distribution: unstable
Urgency: high
Maintainer: PKG OpenStack <openstack-devel@lists.alioth.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Description:
 neutron-common - OpenStack virtual network service - common files
 neutron-dhcp-agent - OpenStack virtual network service - DHCP agent
 neutron-l3-agent - OpenStack virtual network service - l3 agent
 neutron-lbaas-agent - OpenStack virtual network service - LBaaS agent
 neutron-metadata-agent - OpenStack virtual network service - metadata agent
 neutron-metering-agent - OpenStack virtual network service - metering agent
 neutron-plugin-linuxbridge-agent - OpenStack virtual network service - Linux bridge agent
 neutron-plugin-nec-agent - OpenStack virtual network service - NEC agent
 neutron-plugin-openvswitch-agent - OpenStack virtual network service - Open vSwitch agent
 neutron-server - OpenStack virtual network service - server
 neutron-vpn-agent - OpenStack virtual network service - VPN agent
 python-neutron - OpenStack virtual network service - Python library
 python-quantum - transitional dummy package for switching to python-neutron
 quantum-common - transitional dummy package for switching to neutron-common
 quantum-dhcp-agent - transitional dummy package for upgrading quantum-dhcp-agent
 quantum-l3-agent - transitional dummy package for upgrading quantum-l3-agent
 quantum-lbaas-agent - transitional dummy package for upgrading quantum-lbaas-agent
 quantum-metadata-agent - transitional dummy package for upgrading quantum-metadata-agent
 quantum-plugin-bigswitch - transitional dummy package for upgrading quantum-plugin-bigswitch
 quantum-plugin-brocade - transitional dummy package for upgrading quantum-plugin-brocade
 quantum-plugin-cisco - transitional dummy package for upgrading quantum-plugin-cisco
 quantum-plugin-hyperv - transitional dummy package for upgrading quantum-plugin-hyperv
 quantum-plugin-linuxbridge - transitional dummy package for upgrading quantum-plugin-linuxbrid
 quantum-plugin-linuxbridge-agent - transitional dummy package for upgrading quantum-plugin-linuxbrid
 quantum-plugin-metaplugin - transitional dummy package for upgrading quantum-plugin-metaplugi
 quantum-plugin-nec - transitional dummy package for upgrading quantum-plugin-nec
 quantum-plugin-nec-agent - transitional dummy package for upgrading quantum-plugin-nec-agent
 quantum-plugin-nicira - transitional dummy package for upgrading quantum-plugin-nicira
 quantum-plugin-openvswitch - transitional dummy package for upgrading quantum-plugin-openvswit
 quantum-plugin-openvswitch-agent - transitional dummy package for upgrading quantum-plugin-openvswit
 quantum-plugin-plumgrid - transitional dummy package for upgrading quantum-plugin-plumgrid
 quantum-server - transitional dummy package for switching to neutron-server
Closes: 770431
Changes:
 neutron (2014.1.3-6) unstable; urgency=high
 .
   * CVE-2014-7821: DoS through invalid DNS configuration. Applied upstream
     patch: Fix hostname regex pattern (Closes: #770431).
Checksums-Sha1:
 d7e124c441538e213ba97963e58221c7d839e7f8 5549 neutron_2014.1.3-6.dsc
 7e836499fddadf93f16c216bce1db516b1b3b901 45520 neutron_2014.1.3-6.debian.tar.xz
 5537a2091a4184a019e1ea5db1849f53a645e11b 1134132 python-neutron_2014.1.3-6_all.deb
 78fd905a7242095060889215c5607de7774d2e79 23960 neutron-server_2014.1.3-6_all.deb
 99473234c8df2a3b906b962546f00b1a83f7f398 58294 neutron-common_2014.1.3-6_all.deb
 e34c6d0010f3e53d931825402a3eec6e3147f8eb 6096 neutron-plugin-nec-agent_2014.1.3-6_all.deb
 2e74994859e59edfa1e3ad2c4f51aea3eb4a0b12 9692 neutron-l3-agent_2014.1.3-6_all.deb
 f97623bc61fadaae318e61c2f2b8eb78fa964dbf 17868 neutron-dhcp-agent_2014.1.3-6_all.deb
 eb5944ff904ddda6fed5fa0d622c1c7d96515e7f 21054 neutron-metadata-agent_2014.1.3-6_all.deb
 19d686d56111c26f6dcf4aa2688ef310ab8188d2 8480 neutron-metering-agent_2014.1.3-6_all.deb
 5a78a1ba9fdebed324e691acc23d01b885147d32 8550 neutron-vpn-agent_2014.1.3-6_all.deb
 034bcd58680919a2725c68996f7358c795434298 9014 neutron-lbaas-agent_2014.1.3-6_all.deb
 c4827c3316e15a716f1f6f736b41ebb4b0b0763d 8762 neutron-plugin-openvswitch-agent_2014.1.3-6_all.deb
 d6a936e59002b14935e41f21e57c11234edf181e 8606 neutron-plugin-linuxbridge-agent_2014.1.3-6_all.deb
 9e1d5d001b2818e468c24e971ca80b7536733845 5724 python-quantum_2014.1.3-6_all.deb
 29c4938245580f46559d959e417552fcb0e0c088 5718 quantum-server_2014.1.3-6_all.deb
 c64d433fedebe2b8d270d7a257a1601551ed8af6 5724 quantum-common_2014.1.3-6_all.deb
 f13d50a5839fe8a019cd8967e53a350acb7acd99 5732 quantum-plugin-cisco_2014.1.3-6_all.deb
 7d3983b4372275e5ed5b0d6fa45b2f0c631b46b3 5726 quantum-plugin-nec_2014.1.3-6_all.deb
 58581cc7f6dbd3bb4d014113c40e95827c5aaf4b 5736 quantum-plugin-nec-agent_2014.1.3-6_all.deb
 ecea7d8d040caa7529cbcc9a905f7e68cf06cfdf 5734 quantum-plugin-bigswitch_2014.1.3-6_all.deb
 c29809a7f68b64c72cc8abd121d8a73be68adb12 5734 quantum-plugin-hyperv_2014.1.3-6_all.deb
 70764ef4b96f46fd40513d70a7e1afddc9b454f3 5736 quantum-plugin-brocade_2014.1.3-6_all.deb
 e1bbbc2f06ce9ea41df7a629b630bb82f974083f 5728 quantum-plugin-plumgrid_2014.1.3-6_all.deb
 d762dc83457873dd63374eae7258f199310b5aa9 5734 quantum-plugin-metaplugin_2014.1.3-6_all.deb
 648c12d461dde0138d94d1e8b8df85ba1416e13e 5734 quantum-plugin-nicira_2014.1.3-6_all.deb
 2acd2784300828c47185212a7e5e7e0b444e758f 5726 quantum-l3-agent_2014.1.3-6_all.deb
 a174b0c44b272cac2a921c5dba50a3ebdcea13ca 5728 quantum-dhcp-agent_2014.1.3-6_all.deb
 9fc300d31ea622a9d2ca6c3f9cd8556ffb3da297 5738 quantum-metadata-agent_2014.1.3-6_all.deb
 0621f0bfc7e8e0a1b48bb1dc4be1e509e4af12f9 5736 quantum-lbaas-agent_2014.1.3-6_all.deb
 f149691e6a18e8c2c4e148978d27a550d6d4e8ba 5738 quantum-plugin-openvswitch_2014.1.3-6_all.deb
 018560b23870d98cbf34b5f5e7b850382b348fa3 5754 quantum-plugin-openvswitch-agent_2014.1.3-6_all.deb
 d4ed0d836fffdb3c833730093d21cc7e88ac9f14 5742 quantum-plugin-linuxbridge_2014.1.3-6_all.deb
 362200e5e29e869fdc0e4db22753b27c0a3f0ec2 5748 quantum-plugin-linuxbridge-agent_2014.1.3-6_all.deb
Checksums-Sha256:
 2ddcb4cbcd89bd52451302222aec107e638fedcb91bdd7dbcad4f31d319f2999 5549 neutron_2014.1.3-6.dsc
 a6963ad790266dcde4295a11e9ac267ef26ed8627768d87bbe02e14a68e96d38 45520 neutron_2014.1.3-6.debian.tar.xz
 6deab44d07fe45c657674125662d461a46f0fb352706f2f6d02940c2c587dda0 1134132 python-neutron_2014.1.3-6_all.deb
 5c3d4b8c83e92af2ad52c0c96b557a37a7663ce4a20edab082d56b7b374095f2 23960 neutron-server_2014.1.3-6_all.deb
 ec3dbbbd85548c2f04db2f0c430839d83b21cef763d4ff04824ffe5cb68f15b5 58294 neutron-common_2014.1.3-6_all.deb
 aed9d0ae7b69d3803d96d203c7ab8eb7a40355fdc84952d0513fd52eff9e731f 6096 neutron-plugin-nec-agent_2014.1.3-6_all.deb
 eecadeeb93344d0be1238833ce77c1069c539d7eeec9074c1ff330889338e4a5 9692 neutron-l3-agent_2014.1.3-6_all.deb
 3f71ac02cc0aeed650078cc3dc001fe02ae3f2bc123700e89f2b63087f2b7fc3 17868 neutron-dhcp-agent_2014.1.3-6_all.deb
 15879aa54548c14d6c665f53e9c27786388d78c5f1bda633bb6b8fa75ff2f1c0 21054 neutron-metadata-agent_2014.1.3-6_all.deb
 baf794ad57f6ba1883e3734b396f8261c41485dec3f14daee77cab1ba2280752 8480 neutron-metering-agent_2014.1.3-6_all.deb
 e7f551292d337f39da37c7d9dd61b265c4ccd601d86c9515427aaa96907fe1ae 8550 neutron-vpn-agent_2014.1.3-6_all.deb
 d3294bbb07a3e840f2d19f550c7dc6fa42a32fcba6daadcfff31d7b06963c775 9014 neutron-lbaas-agent_2014.1.3-6_all.deb
 f2a98cc318853312e62cf7c2faa806f68447be802277c91a4099a252c54f49fe 8762 neutron-plugin-openvswitch-agent_2014.1.3-6_all.deb
 7209d7be97b8e60da3f53f0b51b4274eea337107dba6e527f0e3aa0fcc523e8e 8606 neutron-plugin-linuxbridge-agent_2014.1.3-6_all.deb
 468d7c4fc6651199a95398ffc008c1e3e0e606e72e162b890a1cb9e4a58d2e2c 5724 python-quantum_2014.1.3-6_all.deb
 19e86679b57e07e3c27f95682b01ae701d7e9c82025e5c1f9566f7ad69e48974 5718 quantum-server_2014.1.3-6_all.deb
 3041a877e7390d13c185799aa3130d12b6bd77689a0b6814634bdba226854f4a 5724 quantum-common_2014.1.3-6_all.deb
 01ebb7f8b677bd9699046b6627fbec52647b905350302488d603ab4bee4d4d73 5732 quantum-plugin-cisco_2014.1.3-6_all.deb
 eca4c8e18d6d1271ea9d652d83dcd7091f1db60dbd7b57d40ad16a600054b98d 5726 quantum-plugin-nec_2014.1.3-6_all.deb
 c601f8a6d81647ff77144c0bd5716c4518ebf7a656a8944f91d4a334f25eff6d 5736 quantum-plugin-nec-agent_2014.1.3-6_all.deb
 41d74cb6d9d4bf58764a74dec9a4358434a36a53e580b81be32686afa387dddc 5734 quantum-plugin-bigswitch_2014.1.3-6_all.deb
 e51094ef15f4953e8f2472a020a3b6a83f857a9914c74b9e47b55db90a12b09b 5734 quantum-plugin-hyperv_2014.1.3-6_all.deb
 a5bcf43c105e0e564f8a1811fdeced03d9f2a64b0b0de817df056d69d66ee966 5736 quantum-plugin-brocade_2014.1.3-6_all.deb
 4877c6775c0797dccca3935168fec68f097e444cdd77ee503c32bee30c0867a5 5728 quantum-plugin-plumgrid_2014.1.3-6_all.deb
 6e17951ebefa412aedfa2efe5b849723186d5c4d3880264e0fcc49378c5f01af 5734 quantum-plugin-metaplugin_2014.1.3-6_all.deb
 9ac7f7e6007ae3a8cebac4f8bfc40e15024453e35e03f483d733a9a5ca8a2cf7 5734 quantum-plugin-nicira_2014.1.3-6_all.deb
 225ccca6de1e24f04266f75d9dd293644cd3ebb1e825c939ba956b14ef74ae8e 5726 quantum-l3-agent_2014.1.3-6_all.deb
 c765f1be1aafffa0692c6a0953973466142ea212956cadb962c25452f6b1f895 5728 quantum-dhcp-agent_2014.1.3-6_all.deb
 bae761f645f391287990b88d6f7d396094a6ea9c0b358bdcb7be48ab3a54cb7f 5738 quantum-metadata-agent_2014.1.3-6_all.deb
 4f2c9576fee5b9fac52666f73d8a5f735b782412fef5732cb4944a375b864d34 5736 quantum-lbaas-agent_2014.1.3-6_all.deb
 aab149d300a4aea7ba7ed209e9260ef1f143edddfc30264f8406f72d1b160b6a 5738 quantum-plugin-openvswitch_2014.1.3-6_all.deb
 7ab20c8d4e1aee98b6d4e87f7475f0d2be074d41a6b9f4f5a439be6736d0aaa9 5754 quantum-plugin-openvswitch-agent_2014.1.3-6_all.deb
 dec995989e60ee06ffd07579171e4a2758d16f05f6c0f9b20698a84dfe3670b9 5742 quantum-plugin-linuxbridge_2014.1.3-6_all.deb
 fa3962433d8c68269481e7a3adf700e48d92fc9755434d9c39651bc1655fb6d1 5748 quantum-plugin-linuxbridge-agent_2014.1.3-6_all.deb
Files:
 67d07cf0f5a908295eb8648170ce5524 5549 net optional neutron_2014.1.3-6.dsc
 5de2dfe4f5f3aca569b5f3b63211213a 45520 net optional neutron_2014.1.3-6.debian.tar.xz
 b6af8e424751587d932e962cd88f95ed 1134132 python optional python-neutron_2014.1.3-6_all.deb
 96376398d4ab4a4af145bc174f6f7a10 23960 net optional neutron-server_2014.1.3-6_all.deb
 1f0bbf206296dcfeb913ee62f3124ccb 58294 net optional neutron-common_2014.1.3-6_all.deb
 c3508d55d01d3288500333d74678699b 6096 net optional neutron-plugin-nec-agent_2014.1.3-6_all.deb
 7617f55f86c33cee02a3a0d1781fbec1 9692 net optional neutron-l3-agent_2014.1.3-6_all.deb
 011343cf9127f333a17dcea24ede38e8 17868 net optional neutron-dhcp-agent_2014.1.3-6_all.deb
 0d3ad7e30efc149a1819de2952658db9 21054 net optional neutron-metadata-agent_2014.1.3-6_all.deb
 7043e3546e79a9502c52d83369d8b071 8480 net optional neutron-metering-agent_2014.1.3-6_all.deb
 c7786537fc17ce173cadd5c765a30896 8550 net optional neutron-vpn-agent_2014.1.3-6_all.deb
 19664984962e33dc15313bd2bee92d14 9014 net optional neutron-lbaas-agent_2014.1.3-6_all.deb
 c61d9c2adc5b311a218ba8dbbdd63010 8762 net optional neutron-plugin-openvswitch-agent_2014.1.3-6_all.deb
 d2a7d378a94b0e16725681df6896bd68 8606 net optional neutron-plugin-linuxbridge-agent_2014.1.3-6_all.deb
 9e4e0cb2473b27862df77f693e81dfa7 5724 oldlibs optional python-quantum_2014.1.3-6_all.deb
 66bf61d0969041e829ffba795b7eafe1 5718 oldlibs optional quantum-server_2014.1.3-6_all.deb
 7f648166848d9ba8333761f62611a44e 5724 oldlibs optional quantum-common_2014.1.3-6_all.deb
 d4021ce9548cb6e3fdeba02ae008afb9 5732 oldlibs optional quantum-plugin-cisco_2014.1.3-6_all.deb
 a858764ea1f419b64afab832113af381 5726 oldlibs optional quantum-plugin-nec_2014.1.3-6_all.deb
 8ec48f74c945f5ffa39e9ea7bb542bee 5736 oldlibs optional quantum-plugin-nec-agent_2014.1.3-6_all.deb
 b7e0355cbe34b3adbe00481f8f90504a 5734 oldlibs optional quantum-plugin-bigswitch_2014.1.3-6_all.deb
 3fbdd8a919a449da64b5debf8bd49843 5734 oldlibs optional quantum-plugin-hyperv_2014.1.3-6_all.deb
 81793fd7c00a4d1e0723c9f4ac6614c9 5736 oldlibs optional quantum-plugin-brocade_2014.1.3-6_all.deb
 b89af66064064f7ee56d6272152c7112 5728 oldlibs optional quantum-plugin-plumgrid_2014.1.3-6_all.deb
 df3436a151ee1382510a613f3244c27b 5734 oldlibs optional quantum-plugin-metaplugin_2014.1.3-6_all.deb
 8ed55f540ba0a4807b719a1257db006c 5734 oldlibs optional quantum-plugin-nicira_2014.1.3-6_all.deb
 c200cdd1eb1090c1e006508c33a00eb5 5726 oldlibs optional quantum-l3-agent_2014.1.3-6_all.deb
 9bfbb34119429292c511b5d4a0064439 5728 oldlibs optional quantum-dhcp-agent_2014.1.3-6_all.deb
 b801e7cdc9f26b1aacceca6d04c87a73 5738 oldlibs optional quantum-metadata-agent_2014.1.3-6_all.deb
 a86aca2146b9b8ca96397ad4203e8c44 5736 oldlibs optional quantum-lbaas-agent_2014.1.3-6_all.deb
 04bf519945d87e68822e4897c7f260ab 5738 oldlibs optional quantum-plugin-openvswitch_2014.1.3-6_all.deb
 2537c5b91de8d3353d29e8ffbcca07c1 5754 oldlibs optional quantum-plugin-openvswitch-agent_2014.1.3-6_all.deb
 729a697f302cb3eb7a6f6e6009557eaa 5742 oldlibs optional quantum-plugin-linuxbridge_2014.1.3-6_all.deb
 6862e437c33711de6e0c304656b520e1 5748 oldlibs optional quantum-plugin-linuxbridge-agent_2014.1.3-6_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCAAGBQJUbwGjAAoJENQWrRWsa0P+Le4P/RwEFVCSiIqu6p5bfhYc4lE5
JpXtPzflzSYRJcd5Z8M0k0vkbToXkIZ8JXJVjAhjK4X6G/RPi53azPqtba+UKYqO
E+v6ZBO7GquoFReRPxojzQRo8Pkfcwkhsx4ICY4CU7ub2iD0TE69oHj64vfCsL8/
0NDtq/HNg0me10U+t3Ri3x6oPN91DhboABtaaDd2bDneIME924ns+lqciI6NhKUo
FlUiLNv5tSwi4A1PDaHB5QCHz4eMZGz3bKa8l5lMgU2k6rsiJUSUtm0zyhj3PI1P
hdPSPvEpE6E5KxlIRQvRunvLv9kTy7ZN+0d2kCHWvC3V3YZB9H1dDtex9evw7fnC
UlagHnGGJHh0AShuytXlSoGibsDDOVhXPwbH+SE+s2JkW3IwOwT6KGCVLxK9zy0L
LKIiB7ZyjK1qJQ/cFI+/H6uoAOvijCOa1NGiYRBhkggdxpU27EIdRUEvbgjPJ94K
6+djAETiJOxo9emQKwf+Wddbs/gVnorrKq14o+nErAp82ojMgxyOr6p8hNTn1cqr
37Oic1RqT8W8E8ZfED1dmGzev+iPNoEEandAAtN/9X5wWE0N03MgKiuP18T6Xoc5
QOfykS+tEI9FtlWeQ8oXpWLjWBOoV8cheRKqBuG6t2aPRwIP+E3yXsRviETka9D8
eoQQsIF3sBD3vGaEaUHA
=G8uC
-----END PGP SIGNATURE-----




Reply sent to Thomas Goirand <zigo@debian.org>:
You have taken responsibility. (Fri, 21 Nov 2014 10:39:05 GMT) (full text, mbox, link).


Notification sent to Thomas Goirand <zigo@debian.org>:
Bug acknowledged by developer. (Fri, 21 Nov 2014 10:39:05 GMT) (full text, mbox, link).


Message #15 received at 770431-close@bugs.debian.org (full text, mbox, reply):

From: Thomas Goirand <zigo@debian.org>
To: 770431-close@bugs.debian.org
Subject: Bug#770431: fixed in neutron 2014.2-4
Date: Fri, 21 Nov 2014 10:34:49 +0000
Source: neutron
Source-Version: 2014.2-4

We believe that the bug you reported is fixed in the latest version of
neutron, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 770431@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated neutron package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Fri, 21 Nov 2014 16:39:03 +0800
Source: neutron
Binary: python-neutron neutron-server neutron-common neutron-plugin-nec-agent neutron-l3-agent neutron-dhcp-agent neutron-metadata-agent neutron-metering-agent neutron-vpn-agent neutron-lbaas-agent neutron-plugin-openvswitch-agent neutron-plugin-linuxbridge-agent python-quantum quantum-server quantum-common quantum-plugin-cisco quantum-plugin-nec quantum-plugin-nec-agent quantum-plugin-bigswitch quantum-plugin-hyperv quantum-plugin-brocade quantum-plugin-plumgrid quantum-plugin-metaplugin quantum-plugin-nicira quantum-l3-agent quantum-dhcp-agent quantum-metadata-agent quantum-lbaas-agent quantum-plugin-openvswitch quantum-plugin-openvswitch-agent quantum-plugin-linuxbridge quantum-plugin-linuxbridge-agent
Architecture: source all
Version: 2014.2-4
Distribution: experimental
Urgency: medium
Maintainer: PKG OpenStack <openstack-devel@lists.alioth.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Description:
 neutron-common - OpenStack virtual network service - common files
 neutron-dhcp-agent - OpenStack virtual network service - DHCP agent
 neutron-l3-agent - OpenStack virtual network service - l3 agent
 neutron-lbaas-agent - OpenStack virtual network service - LBaaS agent
 neutron-metadata-agent - OpenStack virtual network service - metadata agent
 neutron-metering-agent - OpenStack virtual network service - metering agent
 neutron-plugin-linuxbridge-agent - OpenStack virtual network service - Linux bridge agent
 neutron-plugin-nec-agent - OpenStack virtual network service - NEC agent
 neutron-plugin-openvswitch-agent - OpenStack virtual network service - Open vSwitch agent
 neutron-server - OpenStack virtual network service - server
 neutron-vpn-agent - OpenStack virtual network service - VPN agent
 python-neutron - OpenStack virtual network service - Python library
 python-quantum - transitional dummy package for switching to python-neutron
 quantum-common - transitional dummy package for switching to neutron-common
 quantum-dhcp-agent - transitional dummy package for upgrading quantum-dhcp-agent
 quantum-l3-agent - transitional dummy package for upgrading quantum-l3-agent
 quantum-lbaas-agent - transitional dummy package for upgrading quantum-lbaas-agent
 quantum-metadata-agent - transitional dummy package for upgrading quantum-metadata-agent
 quantum-plugin-bigswitch - transitional dummy package for upgrading quantum-plugin-bigswitch
 quantum-plugin-brocade - transitional dummy package for upgrading quantum-plugin-brocade
 quantum-plugin-cisco - transitional dummy package for upgrading quantum-plugin-cisco
 quantum-plugin-hyperv - transitional dummy package for upgrading quantum-plugin-hyperv
 quantum-plugin-linuxbridge - transitional dummy package for upgrading quantum-plugin-linuxbrid
 quantum-plugin-linuxbridge-agent - transitional dummy package for upgrading quantum-plugin-linuxbrid
 quantum-plugin-metaplugin - transitional dummy package for upgrading quantum-plugin-metaplugi
 quantum-plugin-nec - transitional dummy package for upgrading quantum-plugin-nec
 quantum-plugin-nec-agent - transitional dummy package for upgrading quantum-plugin-nec-agent
 quantum-plugin-nicira - transitional dummy package for upgrading quantum-plugin-nicira
 quantum-plugin-openvswitch - transitional dummy package for upgrading quantum-plugin-openvswit
 quantum-plugin-openvswitch-agent - transitional dummy package for upgrading quantum-plugin-openvswit
 quantum-plugin-plumgrid - transitional dummy package for upgrading quantum-plugin-plumgrid
 quantum-server - transitional dummy package for switching to neutron-server
Closes: 770431
Changes:
 neutron (2014.2-4) experimental; urgency=medium
 .
   * CVE-2014-7821: DoS through invalid DNS configuration. Applied upstream
     patch: Fix hostname regex pattern (Closes: #770431).
Checksums-Sha1:
 85af4d7b6dab6a544943e9d6d0fd85ff7a7e4e33 5587 neutron_2014.2-4.dsc
 deb776d87e6bbfc795dcd9ad4a15a757a8919705 45580 neutron_2014.2-4.debian.tar.xz
 b46de3e556aa3c03fc4eb03263898f268e868341 1252628 python-neutron_2014.2-4_all.deb
 14960b45a88c1c1184333a4a25b9330f3dde3ddf 23878 neutron-server_2014.2-4_all.deb
 b02b787945f0c4925ab7f98302fa847280875d66 63336 neutron-common_2014.2-4_all.deb
 b1729720cb3df288ba01cd83089256c02e38ff00 6000 neutron-plugin-nec-agent_2014.2-4_all.deb
 b93a21ec6d142708df16cbc550ec2036e35291e4 9954 neutron-l3-agent_2014.2-4_all.deb
 c76b4b40cc756e05a9058eb2b807cf005acc41f2 17790 neutron-dhcp-agent_2014.2-4_all.deb
 79e119b8da01c0f73e10e7e00b0ec9aab7db1663 21066 neutron-metadata-agent_2014.2-4_all.deb
 79deee89d4a23b6c8c96254df6c1bcdbb1fdadb1 8434 neutron-metering-agent_2014.2-4_all.deb
 0d54bde13a881530b489a797d2bc77a9e5f31350 8474 neutron-vpn-agent_2014.2-4_all.deb
 d3d5637acba2389370969694bc76d52bec2327fc 9026 neutron-lbaas-agent_2014.2-4_all.deb
 367b675e410872e678339ecd94402348700b9485 8672 neutron-plugin-openvswitch-agent_2014.2-4_all.deb
 785d55db293d91bdc21c3b749d178cb27f3ff6f0 8518 neutron-plugin-linuxbridge-agent_2014.2-4_all.deb
 ea0b172b3ca84d262b935aca8ec01d22e984f3c8 5594 python-quantum_2014.2-4_all.deb
 35cc0db2fd7c0b059b0ccff47134d891cc209925 5592 quantum-server_2014.2-4_all.deb
 2294e3f83d4038ab1b7bd8fb43775e4263a430c2 5596 quantum-common_2014.2-4_all.deb
 f7a56e85414d6a4c7143e39816b5cf75297a4d85 5606 quantum-plugin-cisco_2014.2-4_all.deb
 a7dd4c50c8b982482a35acb44876bf4a69ec28b9 5600 quantum-plugin-nec_2014.2-4_all.deb
 e0781f725ef09d1f09ced1fd91f48a4b1d881a34 5612 quantum-plugin-nec-agent_2014.2-4_all.deb
 88ea10cfc6b8fafb5143fd49c3695d72a42ab933 5610 quantum-plugin-bigswitch_2014.2-4_all.deb
 e2f8261666526161c3b65f20e166810994877cb7 5608 quantum-plugin-hyperv_2014.2-4_all.deb
 ce703f361fd0c8f62831a8569d2cfe8d44f3aa88 5608 quantum-plugin-brocade_2014.2-4_all.deb
 79c5ef07a671ee2c45d52d2beb6f04b5e9f087cc 5604 quantum-plugin-plumgrid_2014.2-4_all.deb
 f509befe4dbdb99e044d6a376a676177b119b474 5604 quantum-plugin-metaplugin_2014.2-4_all.deb
 55c4df49593d4b493daea083b5acad72f0c4029c 5604 quantum-plugin-nicira_2014.2-4_all.deb
 5c8d45816d9c06ac0cfeed0240eff37999f6ddd1 5596 quantum-l3-agent_2014.2-4_all.deb
 922637c26cd32125b155d2517824251a04f31072 5598 quantum-dhcp-agent_2014.2-4_all.deb
 37212bb8ae38b1cc1a71a53186da3cfa5491fc9a 5608 quantum-metadata-agent_2014.2-4_all.deb
 f5b320248f5f7575b85eaa71375839007bd1d953 5614 quantum-lbaas-agent_2014.2-4_all.deb
 5b1ab1bf2c5a28271df9d46b8c37dd02134b06bd 5618 quantum-plugin-openvswitch_2014.2-4_all.deb
 17796e9c98ed5adad6be2ef35dd507e097b00ab6 5626 quantum-plugin-openvswitch-agent_2014.2-4_all.deb
 7650664ed12b705c7d403e95c29a42abcd77c1c3 5612 quantum-plugin-linuxbridge_2014.2-4_all.deb
 a95271ec82d9851263fa42ceafb1fa623b209055 5622 quantum-plugin-linuxbridge-agent_2014.2-4_all.deb
Checksums-Sha256:
 6008eab9555661a385ed8e1007914a8e437c1a2cbe3b8bb2c71f04fa5b9697e7 5587 neutron_2014.2-4.dsc
 4d1526065f5cb3aa22af924f2b8800a4ea8395ce7b1429624436dd29585c295d 45580 neutron_2014.2-4.debian.tar.xz
 32909c5a472038c06e2ee690d11c855a0c16d714a2004b77301e60c6d179f4d5 1252628 python-neutron_2014.2-4_all.deb
 c4a9f9300148e22fd63aa05285b0b88a8b946dc11e5473dc92c9abacdc3908d9 23878 neutron-server_2014.2-4_all.deb
 0e3f07053d787b1353d1ea423ff2916d4fa3e612852ae222d217dc54db5486d1 63336 neutron-common_2014.2-4_all.deb
 58fc8198a84b7ebc1752aaea3cd0b62111bd66f4ed1123bc8f734955fa77c210 6000 neutron-plugin-nec-agent_2014.2-4_all.deb
 000dc7f4f66258152267c4858258d9ababc9e44026e4cfc3b87819eeee5e2d2c 9954 neutron-l3-agent_2014.2-4_all.deb
 7f4185cc45429d6651331f98b6590c760ebf46d9b678fb1640c75daa7edd99bf 17790 neutron-dhcp-agent_2014.2-4_all.deb
 3363f9d7b8070b0ec86cac9c8828ec40d75fdc3e8a2563323d6301c7adb57e04 21066 neutron-metadata-agent_2014.2-4_all.deb
 df1bb3acaf84365adb7f77eafb4223388f882c529908b5390b1228463d395215 8434 neutron-metering-agent_2014.2-4_all.deb
 3182599a57b93ce9e0a2c89a6491d8f86d79df5122502321dcb02dc46bbd5707 8474 neutron-vpn-agent_2014.2-4_all.deb
 852c5fd1898a4a9b0256de1cf13443670e0edf375838b134b4fd0f961353fa0c 9026 neutron-lbaas-agent_2014.2-4_all.deb
 e532d06890016eb502a23c07e23423dd1cea323ce621617c6bc782f5b670a8d4 8672 neutron-plugin-openvswitch-agent_2014.2-4_all.deb
 7c72350f614929a737e67f2d1b995dc0d16af871ff43fe8b343611169c4a4dff 8518 neutron-plugin-linuxbridge-agent_2014.2-4_all.deb
 ac1c498866c11bb632a7608f8cb3e68f2f342c3719ef03e121622beceff752c8 5594 python-quantum_2014.2-4_all.deb
 9ac36a0e5f02f99f4f682f33fdbfcefd218ac4133740265b49ee7e3eb3b22291 5592 quantum-server_2014.2-4_all.deb
 e53bf2c59793e7eef0938734c9b191f491f47a2a7e56b7497c0ab66d927c7f36 5596 quantum-common_2014.2-4_all.deb
 88a6083861781fb05b5e30eb8f86429e0055444f5981a5b0f10c4916b40a6866 5606 quantum-plugin-cisco_2014.2-4_all.deb
 c80cc7ba7820b00566ff91fa3fe7fe3bad9cad02822ed6043eb7d49fa82d0cd9 5600 quantum-plugin-nec_2014.2-4_all.deb
 6b5a8334022d6c12122974161b76fff0b0580a2f63ca787fd14277a13b5220bd 5612 quantum-plugin-nec-agent_2014.2-4_all.deb
 e6998e72f26b264745ae8f2145532e3eea3189d9ffa39a410a83d6f490d15885 5610 quantum-plugin-bigswitch_2014.2-4_all.deb
 e221e1a10bb1af6584c36e6a411434c55dc510472a98d7c775bffe08a7c9eddc 5608 quantum-plugin-hyperv_2014.2-4_all.deb
 50ee33984d0b36eb3672fe778d5442bec9497b323f2ef4d1bf873513f53eae62 5608 quantum-plugin-brocade_2014.2-4_all.deb
 3fa0236a92d3a0b7ea53c3262e31045d7df246755a7bd906f6a295c62ec0c408 5604 quantum-plugin-plumgrid_2014.2-4_all.deb
 5b33366d2cfaffbe24887952a0b8a40b27b4f76bf2d9ef12d3d005f6bd6ca506 5604 quantum-plugin-metaplugin_2014.2-4_all.deb
 66dce89722c497244dab8a40a3b02a2088e4caa4362b977e429ab5f75b9f8868 5604 quantum-plugin-nicira_2014.2-4_all.deb
 a44077db2563772992c0b86cbc28613cf1d4cde12157b20df45018f8e731a724 5596 quantum-l3-agent_2014.2-4_all.deb
 8be8c2fefcd60cd0fb05220e28af7d63a2b44ed2cfca5d8472170d676a61dafd 5598 quantum-dhcp-agent_2014.2-4_all.deb
 b4ec8edf388837507908d40246fa1eba763e7abfaa6066f45e19fd1825efcb15 5608 quantum-metadata-agent_2014.2-4_all.deb
 006db774a77dd858a3ceadfa1eb91956c52d1f5d954d47168de8a24ac959fe76 5614 quantum-lbaas-agent_2014.2-4_all.deb
 aac1c2df8a57e3f92152972625e32d454e5558fbd82ac220e88a809f3d2d82c2 5618 quantum-plugin-openvswitch_2014.2-4_all.deb
 4e4a67225027fa7c6987980b43d00a4458e4eaf82ee91995aa798ef9db00e1ec 5626 quantum-plugin-openvswitch-agent_2014.2-4_all.deb
 af5e851d2f73c6f05b23d1924b72a7eb11beb549f150345e82d1885dce1c2516 5612 quantum-plugin-linuxbridge_2014.2-4_all.deb
 083bf4493cd1d097e5d5f5e296c322b0d779d14e511280a81a2a04bae93180d6 5622 quantum-plugin-linuxbridge-agent_2014.2-4_all.deb
Files:
 14a39ca0a8f4bc3619534844b3c79b6a 5587 net optional neutron_2014.2-4.dsc
 6162ddacdf4e207b9269e593f9617125 45580 net optional neutron_2014.2-4.debian.tar.xz
 39f5f3e90cf7510da76cbda88972e668 1252628 python optional python-neutron_2014.2-4_all.deb
 5af338761b1f2ee17dfa051a9822f004 23878 net optional neutron-server_2014.2-4_all.deb
 5ad0e5536425d757ec9039d284c1e13b 63336 net optional neutron-common_2014.2-4_all.deb
 012426ea8b136f4e65161464de6d3394 6000 net optional neutron-plugin-nec-agent_2014.2-4_all.deb
 76a7b416fc73a35cca9e1fbf48c5e59d 9954 net optional neutron-l3-agent_2014.2-4_all.deb
 de0457f99e77d35c46d24f8099003293 17790 net optional neutron-dhcp-agent_2014.2-4_all.deb
 0212da833ba422bbd0d552660ebf070e 21066 net optional neutron-metadata-agent_2014.2-4_all.deb
 99417abe6b9c64e30d996476e918c180 8434 net optional neutron-metering-agent_2014.2-4_all.deb
 3dbbb1ab1d575bcbd978bd06217cd4ff 8474 net optional neutron-vpn-agent_2014.2-4_all.deb
 537962885240c63afdfe8b3e4d68ee9b 9026 net optional neutron-lbaas-agent_2014.2-4_all.deb
 328992d1ec7d6b39f9643a1530fac889 8672 net optional neutron-plugin-openvswitch-agent_2014.2-4_all.deb
 7247bd827ac8ccd262ae14ab8f740206 8518 net optional neutron-plugin-linuxbridge-agent_2014.2-4_all.deb
 c12b8bb25b2353791f88eb17f0458b8d 5594 oldlibs optional python-quantum_2014.2-4_all.deb
 2e4870db5c8cf7063e1f277ac638f3a0 5592 oldlibs optional quantum-server_2014.2-4_all.deb
 ce316e92fe415a78a05c986ac7a4bcbb 5596 oldlibs optional quantum-common_2014.2-4_all.deb
 9b1ce62dbd7f72cdf6ca0eea4bbaf68c 5606 oldlibs optional quantum-plugin-cisco_2014.2-4_all.deb
 f92fe101262a5c9b79d9ef683c022966 5600 oldlibs optional quantum-plugin-nec_2014.2-4_all.deb
 b1cfbf1372c6fd33ff00dcdf75b75177 5612 oldlibs optional quantum-plugin-nec-agent_2014.2-4_all.deb
 1922f34f52bdbc5440336191ea9df0c0 5610 oldlibs optional quantum-plugin-bigswitch_2014.2-4_all.deb
 b02a7724b4c79fa4339b8e26e7a9b1eb 5608 oldlibs optional quantum-plugin-hyperv_2014.2-4_all.deb
 ce89ea7a96be754b358d0fc7b0868fb1 5608 oldlibs optional quantum-plugin-brocade_2014.2-4_all.deb
 8de2e00b3eac8d40acc20108f7aad707 5604 oldlibs optional quantum-plugin-plumgrid_2014.2-4_all.deb
 5214f4c8c187ba2f346d9cfe81aa5b82 5604 oldlibs optional quantum-plugin-metaplugin_2014.2-4_all.deb
 d17a1d6b43f53492bfb4979ca94819c2 5604 oldlibs optional quantum-plugin-nicira_2014.2-4_all.deb
 51c7fba967a7d92d17f3a7fc93d2fd86 5596 oldlibs optional quantum-l3-agent_2014.2-4_all.deb
 faa1b3c13ebd4a02ecdcfc53af44b199 5598 oldlibs optional quantum-dhcp-agent_2014.2-4_all.deb
 3f0ffb760a013940e67112d91d39b2f8 5608 oldlibs optional quantum-metadata-agent_2014.2-4_all.deb
 206d4dc3233dd62f2ed3c80fe60462d8 5614 oldlibs optional quantum-lbaas-agent_2014.2-4_all.deb
 54157a336f6d5eed9a318891842350aa 5618 oldlibs optional quantum-plugin-openvswitch_2014.2-4_all.deb
 c46904918281bdebed1f9fc2af51206d 5626 oldlibs optional quantum-plugin-openvswitch-agent_2014.2-4_all.deb
 17cd041bbdc727181561b14562abc4c2 5612 oldlibs optional quantum-plugin-linuxbridge_2014.2-4_all.deb
 365bc04896051e52fb99bb36157ee447 5622 oldlibs optional quantum-plugin-linuxbridge-agent_2014.2-4_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCAAGBQJUbxJ8AAoJENQWrRWsa0P+6skQAIRV/p3d8Y3Ka+NzvYvompYx
R/RXFoIikVbiN5Iv6k1701qcNtjoDyC7nu5skCBKmCrcyhjV3FDn+1jtg6YKKQwX
d85qv4AtH/aDZo4PadAeH+glqiZzqdwI74Cjy1/L1nhgwMQElIMtMnPImSRbfAxn
1WGzjKax69zv+GojkZzdoaKTL6AIkqU7To8rYsDErDV8bgO4aYA/M7eLoTWBkMXW
Tq/IHLoPo0ZpEcc1rwCQ1Bs/aKfN8p6V9gXA0HKGSvvXz83wWh65FkgzmKP7jxCm
fKp1gF9G6IgsBpUjEgPZEy53Eotpyd9aulN524dcnY5HOe0OqY64bbgwjXqgwSZD
YOK/Brh5ZWyiCi9Bnlcain6VIu5ehPmHtc/IJ/DpGYUvzmqDTawVZrlE8ouhUbGU
GliYRBo6R21Zevw7vxjPhWYITvWAR7mZ53VLJWWuCJWaK5DyETUg9a51UcgfRkC1
BZk8hFxDV125Ld4pHwhCmL9ZDFtsO4vt9hG/Ljjyvd4pgktWDHXcb/dh/2xjCoGe
A3B5SSQwQNEHtOWfAID/I2ZN10Cfj39thzjzJIZoLDjL299UhGm0+fTb3vl3jj8a
5c7ZL0xx4kI+/hCstZppTW6sE3ss4wNx6PQJ3sUEI3TShgn3/Oejj/XIdM+KKJ5k
wOZhlHayFVN0p12mzDQs
=SN7D
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Mon, 22 Dec 2014 07:28:34 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 14:11:05 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.