Lucene search

K
cveRedhatCVE-2013-0250
HistoryJun 06, 2014 - 2:55 p.m.

CVE-2013-0250

2014-06-0614:55:03
redhat
web.nvd.nist.gov
19
cve-2013-0250
corosync
denial of service
crash
remote attackers
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.7

Confidence

High

EPSS

0.013

Percentile

85.9%

The init_nss_hash function in exec/totemcrypto.c in Corosync 2.0 before 2.3 does not properly initialize the HMAC key, which allows remote attackers to cause a denial of service (crash) via a crafted packet.

Affected configurations

Nvd
Node
corosynccorosyncMatch2.0.0
OR
corosynccorosyncMatch2.0.1
OR
corosynccorosyncMatch2.0.2
OR
corosynccorosyncMatch2.0.3
OR
corosynccorosyncMatch2.1.0
OR
corosynccorosyncMatch2.1.1
OR
corosynccorosyncMatch2.2.0
VendorProductVersionCPE
corosynccorosync2.0.0cpe:2.3:a:corosync:corosync:2.0.0:*:*:*:*:*:*:*
corosynccorosync2.0.1cpe:2.3:a:corosync:corosync:2.0.1:*:*:*:*:*:*:*
corosynccorosync2.0.2cpe:2.3:a:corosync:corosync:2.0.2:*:*:*:*:*:*:*
corosynccorosync2.0.3cpe:2.3:a:corosync:corosync:2.0.3:*:*:*:*:*:*:*
corosynccorosync2.1.0cpe:2.3:a:corosync:corosync:2.1.0:*:*:*:*:*:*:*
corosynccorosync2.1.1cpe:2.3:a:corosync:corosync:2.1.1:*:*:*:*:*:*:*
corosynccorosync2.2.0cpe:2.3:a:corosync:corosync:2.2.0:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.7

Confidence

High

EPSS

0.013

Percentile

85.9%