MGASA-2014-0069
Dashboard / Vulnerabilities / MGASA-2014-0069
Summary: Updated pacemaker package fixes one security issue
Details: A denial of service flaw was found in the way Pacemaker performed authentication and processing of remote connections in certain circumstances. When Pacemaker was configured to allow remote Cluster Information Base (CIB) configuration or resource management, a remote attacker could use this flaw to cause Pacemaker to block indefinitely (preventing it from serving other requests) (CVE-2013-0281).
References: https://advisories.mageia.org/MGASA-2014-0069.html, https://bugs.mageia.org/show_bug.cgi?id=11724, https://www.redhat.com/security/data/cve/CVE-2013-0281.html, https://bugzilla.redhat.com/show_bug.cgi?id=891922#c5
Affected packages
Package
Name: pacemaker
Purl: pkg:rpm/mageia/pacemaker?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
