CVE-2015-7944
ganeti - security update
7.5
HIGH
CVSS 3.1
EPSS 14.2%
Description
The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13.x before 2.13.3, 2.14.x before 2.14.2, and 2.15.x before 2.15.2, when used in SSL mode, allows remote attackers to cause a denial of service (resource consumption) via SSL parameter renegotiation.
How to fix CVE-2015-7944
To remediate CVE-2015-7944, upgrade the affected package to a fixed version below.
- —upgrade to 2.15.2-1 or later
- —upgrade to 2.5.2-1+deb7u1 or later
Is CVE-2015-7944 being exploited?
Moderate — EPSS is 14.2%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 2.15.2-1
- from 0, < 2.5.2-1+deb7u1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |