CVE-2017-14491
Find out more about CVE-2017-14491 from the MITRE CVE dictionary dictionary and NIST NVD.
Statement
Red Hat OpenStack Platform には dnsmasq-utils RPM が含まれていますが、この脆弱性で影響を受けるコードパスは含まれていません。このため、Red Hat OpenStack Platform は「影響なし」となっています。
ただし、Red Hat OpenStack Platform の全バージョンは Red Hat Enterprise Linux をベースとしているので、Red Hat OpenStack Platform のユーザーは、('yum update' や 'openstack overcloud update' などの)通常の更新メカニズムを使用して、直ちに Red Hat Enterprise Linux から dnsmasq RPM を必ずアップグレードしてください。
CVSS v2 metrics
| Base Score | 10 |
|---|---|
| Base Metrics | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| Access Vector | Network |
| Access Complexity | Low |
| Authentication | None |
| Confidentiality Impact | Complete |
| Integrity Impact | Complete |
| Availability Impact | Complete |
CVSS v3 metrics
| CVSS3 Base Score | 9.8 |
|---|---|
| CVSS3 Base Metrics | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | None |
| User Interaction | None |
| Scope | Unchanged |
| Confidentiality | High |
| Integrity Impact | High |
| Availability Impact | High |
Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).
Red Hat Security Errata
| Platform | Errata | Release Date |
|---|---|---|
| Red Hat Enterprise Linux Advanced Update Support 6.6 (dnsmasq) | RHSA-2017:2839 | 2017-10-02 |
| Red Hat Enterprise Linux 6 (dnsmasq) | RHSA-2017:2838 | 2017-10-02 |
| Red Hat Enterprise Linux Server (v. 5 ELS) (dnsmasq) | RHSA-2017:2840 | 2017-10-02 |
| Red Hat Enterprise Linux Advanced Update Support 6.2 (dnsmasq) | RHSA-2017:2839 | 2017-10-02 |
| Red Hat Enterprise Linux Long Life (v. 5.9 server) (dnsmasq) | RHSA-2017:2841 | 2017-10-02 |
| Red Hat Enterprise Linux 7 (dnsmasq) | RHSA-2017:2836 | 2017-10-02 |
| Red Hat Enterprise Linux Extended Update Support 7.3 (dnsmasq) | RHSA-2017:2837 | 2017-10-02 |
| Red Hat Enterprise Linux Server TUS (v. 6.5) (dnsmasq) | RHSA-2017:2839 | 2017-10-02 |
| Red Hat Enterprise Linux Extended Update Support 6.7 (dnsmasq) | RHSA-2017:2839 | 2017-10-02 |
| Red Hat Enterprise Linux Extended Update Support 7.2 (dnsmasq) | RHSA-2017:2837 | 2017-10-02 |
| Red Hat Enterprise Linux Advanced Update Support 6.4 (dnsmasq) | RHSA-2017:2839 | 2017-10-02 |
| Red Hat Enterprise Linux Advanced Update Support 6.5 (dnsmasq) | RHSA-2017:2839 | 2017-10-02 |
| Red Hat Enterprise Linux Server TUS (v. 6.6) (dnsmasq) | RHSA-2017:2839 | 2017-10-02 |
Affected Packages State
| Platform | Package | State |
|---|---|---|
| Red Hat OpenStack Platform 9.0 | dnsmasq | 影響なし |
| Red Hat OpenStack Platform 8.0 (Liberty) | dnsmasq | 影響なし |
| Red Hat OpenStack Platform 12 | dnsmasq | 影響なし |
| Red Hat OpenStack Platform 11 | dnsmasq | 影響なし |
| Red Hat OpenStack Platform 10 | dnsmasq | 影響なし |
| Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 | dnsmasq | 影響なし |
| Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 | dnsmasq | 影響なし |
