Linbit Csync2 vulnerabilities
2 known vulnerabilities affecting linbit/csync2.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2019-15523MEDIUMCVSS 5.3≤ 2.02020-12-30
CVE-2019-15523 [MEDIUM] CWE-252 CVE-2019-15523: An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the return val
An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the return value GNUTLS_E_WARNING_ALERT_RECEIVED of the gnutls_handshake() function. It neglects to call this function again, as required by the design of the API.
nvdosv
CVE-2019-15522CRITICALCVSS 9.8≤ 2.02020-03-20
CVE-2019-15522 [CRITICAL] CVE-2019-15522: An issue was discovered in LINBIT csync2 through 2.0. csync_daemon_session in daemon.c neglects to f
An issue was discovered in LINBIT csync2 through 2.0. csync_daemon_session in daemon.c neglects to force a failure of a hello command when the configuration requires use of SSL.
nvdosv