First published: Tue Nov 12 2019(Updated: )
Pacemaker before 1.1.6 configure script creates temporary files insecurely
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Clusterlabs Pacemaker | <1.1.6 | |
debian/pacemaker | 2.0.5-2 2.1.5-1+deb12u1 2.1.8~rc4-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-5271 is a vulnerability in Pacemaker before version 1.1.6 that allows the creation of temporary files insecurely.
Clusterlabs Pacemaker versions up to, but not including, 1.1.6 are affected. Additionally, some versions of the pacemaker package in Debian are also affected.
CVE-2011-5271 has a severity rating of 5.5 (medium).
To fix CVE-2011-5271, you should update your Pacemaker installation to version 1.1.6 or later. If you are using the Debian package, you can update to one of the specified versions.
You can find more information about CVE-2011-5271 at the following references: [1] [2] [3].