Vulnerability CVE-2016-7797


Published: 2017-03-24

Description:
Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthenticated connection.

Type:

CWE-254

(Security Features)

Vendor: Redhat
Product: Enterprise linux resilient storage 
Version: 7.0;
Product: Enterprise linux high availability 
Version: 7.0;
Vendor: Opensuse
Product: LEAP 
Version: 42.2;
Vendor: Opensuse project
Product: LEAP 
Version: 42.2; 42.1;
Vendor: SUSE
Product: Linux enterprise software development kit 
Version: 12;
Product: Linux enterprise high availability 
Version: 12;
Vendor: Clusterlabs
Product: Pacemaker 
Version: 1.1.14;

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial

 References:
http://bugs.clusterlabs.org/show_bug.cgi?id=5269
http://lists.opensuse.org/opensuse-security-announce/2016-11/msg00038.html
http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00001.html
http://lists.opensuse.org/opensuse-updates/2016-12/msg00077.html
http://rhn.redhat.com/errata/RHSA-2016-2578.html
http://www.openwall.com/lists/oss-security/2016/10/01/1
http://www.securityfocus.com/bid/93261
https://github.com/ClusterLabs/pacemaker/commit/5ec24a2642bd0854b884d1a9b51d12371373b410

Related CVE
CVE-2011-5271
Pacemaker before 1.1.6 configure script creates temporary files insecurely
CVE-2019-10153
A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest VM's comment or other fields would cause fence_rhevm to exit with an exception. In cluster environments, this could lead to preventing automate...
CVE-2019-12779
libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /tmp) without O_EXCL.
CVE-2019-3885
A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in certain sensitive information to be leaked via the system logs.
CVE-2018-16878
A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processes can lead to DoS
CVE-2018-16877
A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attacker could use this flaw, and combine it with other IPC weaknesses, to achieve local privilege escalation.
CVE-2016-7035
An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manager daemon t...
CVE-2018-1086
pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensitive information. A remote att...

Copyright 2019, cxsecurity.com

 

Back to Top