PT-2009-2030 · Red Hat · Cman - The Cluster Manager
Tomas Hoger
·
Published
2009-03-31
·
Updated
2017-08-17
·
CVE-2008-6560
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
CMAN - The Cluster Manager versions prior to 2.03.09-1
Description
A buffer overflow issue exists, allowing attackers to cause a denial of service through CPU consumption and memory corruption by using a cluster.conf file with many lines. It is unclear whether this issue can cross privilege boundaries in realistic uses of the product.
Recommendations
For CMAN - The Cluster Manager versions prior to 2.03.09-1, update to version 2.03.09-1 or later to resolve the issue. As a temporary workaround, consider restricting access to the cluster.conf file to minimize the risk of exploitation.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cman - The Cluster Manager