CVE-2015-5240
27.10.2015, 16:59
Race condition in OpenStack Neutron before 2014.2.4 and 2015.1 before 2015.1.2, when using the ML2 plugin or the security groups AMQP API, allows remote authenticated users to bypass IP anti-spoofing controls by changing the device owner of a port to start with network: before the security group rules are applied.
Vendor | Product | Version |
---|---|---|
openstack | neutron | 2014.2.3 |
openstack | neutron | 2015.1.0 |
openstack | neutron | 2015.1.1 |
𝑥
= Vulnerable software versions

Debian Releases
References