PT-2013-2214 · Clusterlabs+3 · Pacemaker+3

David Vossel

+1

·

Published

2013-11-20

·

Updated

2019-04-22

·

CVE-2013-0281

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Pacemaker version 1.1.10
Description The issue allows remote attackers to cause a denial of service, specifically connection blocking, when remote Cluster Information Base (CIB) configuration or resource management is enabled. This occurs because the duration of connections to the blocking sockets is not limited.
Recommendations For Pacemaker version 1.1.10, consider disabling remote CIB configuration or resource management as a temporary workaround to minimize the risk of exploitation. Restrict access to the blocking sockets to prevent connection blocking.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1923
CESA-2013_1635
CVE-2013-0281
MGASA-2014-0069
RHSA-2013:1635
RHSA-2013_1635

Affected Products

Alt Linux
Centos
Pacemaker
Red Hat