CVE-2014-0187

Publication date 28 April 2014

Last updated 24 July 2024


Ubuntu priority

The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to bypass security group restrictions via an invalid CIDR in a security group rule, which prevents further rules from being applied.

Status

Package Ubuntu Release Status
neutron 14.04 LTS trusty
Fixed 1:2014.1-0ubuntu1.3
13.10 saucy
Fixed 1:2013.2.3-0ubuntu1.5
12.10 quantal Not in release
12.04 LTS precise Not in release
10.04 LTS lucid Not in release

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
neutron

References

Related Ubuntu Security Notices (USN)

    • USN-2255-1
    • OpenStack Neutron vulnerabilities
    • 25 June 2014

Other references