PT-2020-9705 · Linbit+2 · Csync2+2
Published
2020-03-20
·
Updated
2024-12-25
·
CVE-2019-15522
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LINBIT csync2 versions through 2.0
Description
An issue was discovered in LINBIT csync2 where the
csync daemon session in daemon.c neglects to force a failure of a hello command when the configuration requires use of SSL.Recommendations
For versions through 2.0, as a temporary workaround, consider disabling the
csync daemon session function until a patch is available. Restrict access to the daemon.c module to minimize the risk of exploitation. Avoid using the SSL configuration in the affected csync2 until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Suse
Csync2