CVE Vulnerabilities

CVE-2006-3121

Published: Aug 17, 2006 | Modified: Jul 20, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

The peel_netstring function in cl_netstring.c in the heartbeat subsystem in High-Availability Linux before 1.2.5, and 2.0 before 2.0.7, allows remote attackers to cause a denial of service (crash) via the length parameter in a heartbeat message.

Affected Software

Name Vendor Start Version End Version
Heartbeat High_availability_linux_project 2.0.2 2.0.2
Heartbeat High_availability_linux_project 2.0.5 2.0.5
Heartbeat High_availability_linux_project 1.2.4 1.2.4
Heartbeat High_availability_linux_project 1.2.3 1.2.3
Heartbeat High_availability_linux_project 2.0.4 2.0.4
Heartbeat High_availability_linux_project 2.0.1 2.0.1
Heartbeat High_availability_linux_project 2.0.3 2.0.3
Heartbeat High_availability_linux_project 2.0.6 2.0.6

References