MEDIUM
pacemaker: remote DoS when CIB management is enabled caused by use of blocking sockets
Published Nov 23, 2013
4.3
MEDIUMCVSS 2.0
EPSS 2.61%
Description
Pacemaker 1.1.10, when remote Cluster Information Base (CIB) configuration or resource management is enabled, does not limit the duration of connections to the blocking sockets, which allows remote attackers to cause a denial of service (connection blocking).
Affected products
No data.
Configuration 1
- 6.0
Configuration 2
- 1.1.10
No data.
Red Hat Enterprise Linux 6
pacemaker-0:1.1.10-14.el6
Fixed · RHSA-2013:1635
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | pacemaker-0:1.1.10-14.el6 | Fixed | RHSA-2013:1635 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- http://rhn.redhat.com/errata/RHSA-2013-1635.html vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/security/cve/CVE-2013-0281 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=891922 x_refsource_CONFIRMIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-0305 Advisory
- https://github.com/ClusterLabs/pacemaker/commit/564f7cc2a51dcd2f28ab12a13394f31be5aa3c93 x_refsource_CONFIRMExploitPatch
- https://nvd.nist.gov/vuln/detail/CVE-2013-0281
- https://www.cve.org/CVERecord?id=CVE-2013-0281
| Link | Providers | Tags |
|---|---|---|
| http://rhn.redhat.com/errata/RHSA-2013-1635.html | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2013-0281 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=891922 | x_refsource_CONFIRMIssue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-0305 | Advisory | |
| https://github.com/ClusterLabs/pacemaker/commit/564f7cc2a51dcd2f28ab12a13394f31be5aa3c93 | x_refsource_CONFIRMExploitPatch | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-0281 | ||
| https://www.cve.org/CVERecord?id=CVE-2013-0281 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 23, 2013
Updated Aug 6, 2024
Reserved Dec 6, 2012
Link CVE-2013-0281
CISA Vulnrichment
No data
GitHub
No data