Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Alain Moulle

Pesquisador deATOS/BULL
#16456de 53,638
16.3CVSS total
Vulnerabilidades · 2
Alta
2
PT-2016-7189
8.8
2016-11-03
Clusterlabs · Pacemaker · CVE-2016-7035
**Name of the Vulnerable Software and Affected Versions** Pacemaker versions prior to 1.1.16 **Description** An authorization flaw was found where Pacemaker did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to gain root access on the machine, for example, by forcing the Local Resource Manager daemon to execute a script as root. **Recommendations** For versions prior to 1.1.16, update to version 1.1.16 or later to resolve the issue. As a temporary workaround, consider restricting access to the IPC interface to minimize the risk of exploitation.
PT-2017-9350
7.5
2016-06-27
Clusterlabs · Pacemaker · CVE-2016-7797
**Name of the Vulnerable Software and Affected Versions** Pacemaker versions prior to 1.1.15 **Description** The issue allows remote attackers to cause a denial of service, specifically node disconnection, via an unauthenticated connection when using pacemaker remote. **Recommendations** For versions prior to 1.1.15, update to version 1.1.15 or later to resolve the issue.