Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux

CVE-2016-0738
CVE information
Published
Last Modified
CVSSv2.0 Severity
CVSSv3.1 Severity
Impact Analysis
Description
A memory-leak issue was found in OpenStack Object Storage (swift), in the proxy-to-server connection. An OpenStack-authenticated attacker could remotely trigger this flaw to cause denial of service through excess memory consumption..
CVSSv2.0 Score
- Severity
- Medium
- Base Score
- 5/10
- Exploit Score
- 10/10
- Access Vector
- Network
- Access Complexity
- Low
- Authentication Required
- None
- Impact Score
- 2.9/10
- Confidentiality Impact
- None
- Availability Impact
- Partial
- Integrity Impact
- None
CVSSv3.1 Score
- Severity
- High
- Base Score
- 7.5/10
- Exploit Score
- 3.9/10
- Access Vector
- Network
- Access Complexity
- Low
- Privileges Required
- None
- Impact Score
- 3.6/10
- Confidentiality Impact
- None
- Availability Impact
- High
- Integrity Impact
- None
- Scope
- Unchanged
- User Interaction
- None
Products Affected
CPE | Affected | Vulnerable | Excluding | Edit |
---|---|---|---|---|
cpe:2.3:a:openstack:swift:2.5.0:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:openstack:swift:2.4.0:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:openstack:swift:*:*:*:*:*:*:*:* |
Yes
|
- | - |
References
- https://security.openstack.org/ossa/OSSA-2016-004.html
- https://github.com/openstack/swift/blob/master/CHANGELOG
- https://bugs.launchpad.net/cloud-archive/+bug/1493303
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/81432
- http://rhn.redhat.com/errata/RHSA-2016-0128.html
- http://rhn.redhat.com/errata/RHSA-2016-0155.html
- http://rhn.redhat.com/errata/RHSA-2016-0329.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176713.html
- https://access.redhat.com/security/cve/CVE-2016-0738
- https://bugzilla.redhat.com/show_bug.cgi?id=1298905
- https://access.redhat.com/errata/RHSA-2016:0329
- https://access.redhat.com/errata/RHSA-2016:0328
- https://access.redhat.com/errata/RHSA-2016:0155
- https://access.redhat.com/errata/RHSA-2016:0128
- https://access.redhat.com/errata/RHSA-2016:0127
- https://access.redhat.com/errata/RHSA-2016:0126