[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256148

 
 

909

 
 

199106

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-0250Date: (C)2014-06-16   (M)2023-12-22


The init_nss_hash function in exec/totemcrypto.c in Corosync 2.0 before 2.3 does not properly initialize the HMAC key, which allows remote attackers to cause a denial of service (crash) via a crafted packet.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: NONE
Availability: PARTIAL
  
Reference:
SECUNIA-52037
http://seclists.org/oss-sec/2013/q1/212
http://seclists.org/oss-sec/2013/q1/213
http://seclists.org/oss-sec/2013/q1/214
https://github.com/corosync/corosync/commit/b3f456a8ceefac6e9f2e9acc2ea0c159d412b595

CPE    7
cpe:/a:corosync:corosync:2.1.0
cpe:/a:corosync:corosync:2.0.1
cpe:/a:corosync:corosync:2.0.0
cpe:/a:corosync:corosync:2.0.3
...

© SecPod Technologies