The peel_netstring function in cl_netstring.c in the heartbeat subsystem in High-Availability Linux before 1.2.5, and 2.0 before 2.0.7, allows remote attackers to cause a denial of service (crash) via the length parameter in a heartbeat message.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Heartbeat | High_availability_linux_project | 1.2.3 (including) | 1.2.3 (including) |
Heartbeat | High_availability_linux_project | 1.2.4 (including) | 1.2.4 (including) |
Heartbeat | High_availability_linux_project | 2.0.1 (including) | 2.0.1 (including) |
Heartbeat | High_availability_linux_project | 2.0.2 (including) | 2.0.2 (including) |
Heartbeat | High_availability_linux_project | 2.0.3 (including) | 2.0.3 (including) |
Heartbeat | High_availability_linux_project | 2.0.4 (including) | 2.0.4 (including) |
Heartbeat | High_availability_linux_project | 2.0.5 (including) | 2.0.5 (including) |
Heartbeat | High_availability_linux_project | 2.0.6 (including) | 2.0.6 (including) |
Heartbeat | Ubuntu | dapper | * |
Heartbeat | Ubuntu | devel | * |
Heartbeat | Ubuntu | edgy | * |
Heartbeat | Ubuntu | feisty | * |