Bug 874757 (CVE-2014-0187) - VUL-0: CVE-2014-0187: openstack-neutron: security groups bypass through invalid CIDR
Summary: VUL-0: CVE-2014-0187: openstack-neutron: security groups bypass through inval...
Status: RESOLVED FIXED
Alias: CVE-2014-0187
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Deadline: 2014-05-28
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/98143/
Whiteboard: maint:released:sle11-sp3-uptu:57435
Keywords:
Depends on:
Blocks:
 
Reported: 2014-04-23 09:38 UTC by Alexander Bergmann
Modified: 2015-02-19 01:49 UTC (History)
7 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2014-04-23 09:38:12 UTC
Via rh#1090132:

OpenStack Security Advisory: 2014-014
CVE: CVE-2014-0187
Date: April 22, 2014
Title: Neutron security groups bypass through invalid CIDR
Reporters: Stephen Ma (HP) and Christoph Thiel (Deutsche Telekom)
Products: Neutron
Versions: 2013.1 to 2013.2.3, and 2014.1

Description:
Stephen Ma from Hewlett Packard and Christoph Thiel from Deutsche
Telekom reported a vulnerability in Neutron security groups. By creating
a security group rule with an invalid CIDR, an authenticated user may
break openvswitch-agent process, preventing further rules from being
applied on the host. Note: removal of the faulty rule is not enough, the
openvswitch-agent must be restarted. All Neutron setups using Open
vSwitch are affected.

Juno (development branch) fix:
https://review.openstack.org/59212

Icehouse fix:
https://review.openstack.org/88674

Havana fix:
https://review.openstack.org/88057

Notes:
This fix will be included in the juno-1 development milestone and in
future 2013.2.4 and 2014.1.1 releases.

References:
https://launchpad.net/bugs/1300785
https://bugzilla.redhat.com/show_bug.cgi?id=1090132
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0187
Comment 1 Swamp Workflow Management 2014-04-23 22:00:48 UTC
bugbot adjusting priority
Comment 2 Nanuk Krinner 2014-05-13 22:38:50 UTC
sr#37836 has the package with the fix
Comment 3 Swamp Workflow Management 2014-05-14 06:08:52 UTC
The SWAMPID for this issue is 57386.
This issue was rated as moderate.
Please submit fixed packages until 2014-05-28.
When done, please reassign the bug to security-team@suse.de.
Patchinfo will be handled by security team.
Comment 5 Marcus Meissner 2014-05-26 12:46:03 UTC
how can our QA test this?
Comment 6 Vincent Untz 2014-05-26 14:37:36 UTC
(In reply to comment #5)
> how can our QA test this?

https://bugzilla.redhat.com/show_bug.cgi?id=1090132#c3 provides the info about how to see the bug (and therefore how to see the fix is working)
Comment 7 Swamp Workflow Management 2014-06-04 13:46:34 UTC
Update released for: openstack-neutron, openstack-neutron-dhcp-agent, openstack-neutron-doc, openstack-neutron-ha-tool, openstack-neutron-hyperv-agent, openstack-neutron-l3-agent, openstack-neutron-lbaas-agent, openstack-neutron-linuxbridge-agent, openstack-neutron-metadata-agent, openstack-neutron-metering-agent, openstack-neutron-mlnx-agent, openstack-neutron-nec-agent, openstack-neutron-openvswitch-agent, openstack-neutron-plugin-cisco, openstack-neutron-ryu-agent, openstack-neutron-server, openstack-neutron-test, openstack-neutron-vmware-agent, openstack-neutron-vpn-agent, python-neutron
Products:
SUSE-CLOUD 3.0 (x86_64)
Comment 8 Swamp Workflow Management 2014-06-04 17:04:25 UTC
SUSE-SU-2014:0754-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 874757
CVE References: CVE-2014-0187
Sources used:
SUSE Cloud 3 (src):    openstack-neutron-2013.2.4.dev54.gc78491e-0.7.1, openstack-neutron-doc-2013.2.4.dev54.gc78491e-0.7.1
Comment 11 Bernhard Wiedemann 2014-07-07 09:52:33 UTC
submitted
https://build.opensuse.org/request/show/239770 13.1 / openstack-neutron
Comment 13 Swamp Workflow Management 2014-08-21 14:04:22 UTC
openSUSE-SU-2014:1051-1: An update that contains security fixes can now be installed.

Category: security (moderate)
Bug References: 874757
CVE References: 
Sources used:
openSUSE 13.1 (src):    openstack-neutron-2013.2.4.dev86.gb4b09a6-4.1, openstack-neutron-doc-2013.2.4.dev86.gb4b09a6-4.1, python-eventlet-0.14.0-2.4.1, python-greenlet-0.4.2-3.4.1, python-iso8601-0.1.10-6.4.1, python-neutronclient-2.3.4-6.1, python-py-1.4.22-2.4.1, python-pytest-2.6.0-2.4.1