[Openstack-security] [openstack/neutron] SecurityImpact review request change Ic115eeb59cbacdafb85296d435322ea8b8cc99d6

gerrit2 at review.openstack.org gerrit2 at review.openstack.org
Tue Apr 28 04:55:52 UTC 2015


Hi, I'd like you to take a look at this patch for potential
SecurityImpact.
https://review.openstack.org/157634

Log:
commit b94b26f41119b007a0931f839972335138d76259
Author: Juergen Brendel <jbrendel at cisco.com>
Date:   Fri Mar 20 14:40:35 2015 +1300

    ARP spoofing patch: Ebtables manager
    
    ARP cache poisoning is not actually prevented by the firewall
    driver 'iptables_firewall'. We are adding the use of the ebtables
    command - with a corresponding ebtables-driver - in order to create
    Ethernet frame filtering rules, which prevent the sending of ARP
    cache poisoning frames.
    
    The complete patch is broken into smaller patch sets for easier review.
    
    This patch set here includes the ebtables manager class.
    
    Note:
        This commit is based greatly on an original, now abandoned patch,
        presented for review here:
    
            https://review.openstack.org/#/c/70067/
    
    Full spec can be found here: https://review.openstack.org/#/c/129090/
    
    SecurityImpact
    
    Change-Id: Ic115eeb59cbacdafb85296d435322ea8b8cc99d6
    Implements: blueprint arp-spoof-patch-ebtables
    Related-Bug: 1274034
    Co-Authored-By: jbrendel <jbrendel at cisco.com>





More information about the Openstack-security mailing list