CVE-2013-0281

CWE-3998 documents7 sources
Severity
4.3MEDIUM
EPSS
0.7%
top 28.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 23
Latest updateMay 5

Description

Pacemaker 1.1.10, when remote Cluster Information Base (CIB) configuration or resource management is enabled, does not limit the duration of connections to the blocking sockets, which allows remote attackers to cause a denial of service (connection blocking).

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

Debianpacemaker< 1.1.10-1+3

Also affects: Enterprise Linux 6.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-9mhm-24f3-gp3v: Pacemaker 12022-05-05
OSV
CVE-2013-0281: Pacemaker 12013-11-23
CVEList
CVE-2013-0281: Pacemaker 12013-11-23

📋Vendor Advisories

2
Red Hat
pacemaker: remote DoS when CIB management is enabled caused by use of blocking sockets2013-02-14
Debian
CVE-2013-0281: pacemaker - Pacemaker 1.1.10, when remote Cluster Information Base (CIB) configuration or re...2013

💬Community

2
Bugzilla
CVE-2013-0281 pacemaker: Denial of service when remote CIB management enabled due to use of no-timeout blocking socket to wait for the arrival of the authentication credentials [fedora-all]2013-02-14
Bugzilla
CVE-2013-0281 pacemaker: remote DoS when CIB management is enabled caused by use of blocking sockets2013-01-04
CVE-2013-0281 (MEDIUM CVSS 4.3) | Pacemaker 1.1.10 | cvebase.io