VulnerabilityModified
CVE-2013-0281
Pacemaker 1.1.10, when remote Cluster Information Base (CIB) configuration or resource management is enabled, does not limit the duration of connections to the blocking sockets, which allows remote attackers to cause a denial of service (connection…
MEDIUM 4.3EPSS 2.61%
Does this matter?
Lower severity and a low EPSS score (2.61%). Track it; it rarely justifies an emergency change on its own.
Description
Pacemaker 1.1.10, when remote Cluster Information Base (CIB) configuration or resource management is enabled, does not limit the duration of connections to the blocking sockets, which allows remote attackers to cause a denial of service (connection blocking).
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
- EPSS
- 2.61% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- redhat/enterprise linux · clusterlabs/pacemaker
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2013-1635.htmlVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=891922
- https://github.com/ClusterLabs/pacemaker/commit/564f7cc2a51dcd2f28ab12a13394f31be5aa3c93Exploit, Patch
- http://rhn.redhat.com/errata/RHSA-2013-1635.htmlVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=891922
- https://github.com/ClusterLabs/pacemaker/commit/564f7cc2a51dcd2f28ab12a13394f31be5aa3c93Exploit, Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.