Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-6560

Overview

Vulnerability Score 7.8 7.8
CVE Id CVE-2008-6560
Last Modified 23 Dec 2009 01:50:47
Published 31 Mar 2009 10:09:53
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2008-6560

Summary

Buffer overflow in CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9 and Red Hat Enterprise Linux (RHEL) 5 allows attackers to cause a denial of service (CPU consumption and memory corruption) via a cluster.conf file with many lines. NOTE: it is not clear whether this issue crosses privilege boundaries in realistic uses of the product.

Vulnerable Systems

Application

  • Redhat Cman 2.03.03-1

  • Redhat Cman 2.03.04-1

  • Redhat Cman 2.03.05-1

  • Redhat Cman 2.03.07-1

  • Redhat Cman 2.03.08-1


References

CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=468966

XF - cman-clusterconf-dos(49832)

UBUNTU - USN-875-1

FEDORA - FEDORA-2008-9458

CONFIRM - http://git.fedorahosted.org/git/cluster.git?p=cluster.git;a=commitdiff;h=67fee9128e54c6c3fc3eae306b5b501f3029c3be


Last Updated: 27 May 2016 10:49:14