CVE Vulnerabilities

CVE-2013-0250

Published: Jun 06, 2014 | Modified: Jun 09, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM

The init_nss_hash function in exec/totemcrypto.c in Corosync 2.0 before 2.3 does not properly initialize the HMAC key, which allows remote attackers to cause a denial of service (crash) via a crafted packet.

Affected Software

Name Vendor Start Version End Version
Corosync Corosync 2.0.0 (including) 2.0.0 (including)
Corosync Corosync 2.0.1 (including) 2.0.1 (including)
Corosync Corosync 2.0.2 (including) 2.0.2 (including)
Corosync Corosync 2.0.3 (including) 2.0.3 (including)
Corosync Corosync 2.1.0 (including) 2.1.0 (including)
Corosync Corosync 2.1.1 (including) 2.1.1 (including)
Corosync Corosync 2.2.0 (including) 2.2.0 (including)

References