PT-2020-9705 · Linbit+2 · Csync2+2

Published

2020-03-20

·

Updated

2024-12-25

·

CVE-2019-15522

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LINBIT csync2 versions through 2.0
Description An issue was discovered in LINBIT csync2 where the csync daemon session in daemon.c neglects to force a failure of a hello command when the configuration requires use of SSL.
Recommendations For versions through 2.0, as a temporary workaround, consider disabling the csync daemon session function until a patch is available. Restrict access to the daemon.c module to minimize the risk of exploitation. Avoid using the SSL configuration in the affected csync2 until the issue is resolved.

Fix

Related Identifiers

ALT-PU-2023-7630
ALT-PU-2023-7632
ALT-PU-2023-7754
ALT-PU-2024-17519
CVE-2019-15522
OPENSUSE-SU-2021:0853-1
OPENSUSE-SU-2021_0853-1
OPENSUSE-SU-2024:10706-1
SUSE-SU-2021:14763-1
SUSE-SU-2021:1858-1
SUSE-SU-2021:1952-1
SUSE-SU-2021_14763-1
SUSE-SU-2021_1858-1
SUSE-SU-2021_1952-1

Affected Products

Alt Linux
Suse
Csync2