CVE-2009-0242: Ganglia gmetad vulnerability
REJECT gmetad in Ganglia 3.1.1, when supporting multiple requests per connection on an interactive port, allows remote attackers to cause a denial of service via a request to the gmetad service with a path that does not exist, which causes Ganglia to (1) perform excessive CPU computation and (2) send the entire tree, which consumes network bandwidth. NOTE: the vendor and original researcher have disputed this issue, since legitimate requests can generate the same amount of resource consumption. CVE concurs with the dispute, so this identifier should not be used.
Other sources
Rejected reason: gmetad in Ganglia 3.1.1, when supporting multiple requests per connection on an interactive port, allows remote attackers to cause a denial of service via a request to the gmetad service with a path that does not exist, which causes Ganglia to (1) perform excessive CPU computation and (2) send the entire tree, which consumes network bandwidth. NOTE: the vendor and original researcher have disputed this issue, since legitimate requests can generate the same amount of resource consumption. CVE concurs with the dispute, so this identifier should not be used
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0242?
CVE-2009-0242 is classified as a denial of service vulnerability affecting Ganglia gmetad.
How do I fix CVE-2009-0242?
To mitigate CVE-2009-0242, it is recommended to upgrade to a newer version of Ganglia that addresses this vulnerability.
What type of attack does CVE-2009-0242 enable?
CVE-2009-0242 allows remote attackers to perform denial of service attacks on the gmetad service.
Which version of Ganglia gmetad is affected by CVE-2009-0242?
CVE-2009-0242 specifically affects Ganglia gmetad version 3.1.1.
Is CVE-2009-0242 a known vulnerability in gmetad?
Yes, CVE-2009-0242 is a documented vulnerability in gmetad that has been recognized by security researchers.