Pacemaker 1.1.10, when remote Cluster Information Base (CIB) configuration or resource management is enabled, does not limit the duration of connections to the blocking sockets, which allows remote attackers to cause a denial of service (connection blocking).
Name | Vendor | Start Version | End Version |
---|---|---|---|
Enterprise_linux | Redhat | 6.0 (including) | 6.0 (including) |
Red Hat Enterprise Linux 6 | RedHat | pacemaker-0:1.1.10-14.el6 | * |
Pacemaker | Ubuntu | lucid | * |
Pacemaker | Ubuntu | oneiric | * |
Pacemaker | Ubuntu | precise | * |
Pacemaker | Ubuntu | quantal | * |
Pacemaker | Ubuntu | raring | * |
Pacemaker | Ubuntu | saucy | * |
Pacemaker | Ubuntu | upstream | * |