CVE-2013-0250: Medium severity corosync corosync vulnerability
Published Jun 6, 2014
·Updated
The initnsshash function in exec/totemcrypto.c in Corosync 2.0 before 2.3 does not properly initialize the HMAC key, which allows remote attackers to cause a denial of service (crash) via a crafted packet.
Affected Software
7 affected components
corosync corosync=2.0.0
corosync corosync=2.0.1
corosync corosync=2.0.2
corosync corosync=2.0.3
corosync corosync=2.1.0
corosync corosync=2.1.1
corosync corosync=2.2.0
Remediation
Event History
Jun 6, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:55 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-0250?
CVE-2013-0250 is classified as a denial of service vulnerability that can lead to application crashes.
2
How do I fix CVE-2013-0250?
To resolve CVE-2013-0250, upgrade Corosync to version 2.3 or later.
3
Which versions of Corosync are affected by CVE-2013-0250?
CVE-2013-0250 affects Corosync versions 2.0.0 through 2.2.0.
4
What type of attack does CVE-2013-0250 facilitate?
CVE-2013-0250 allows remote attackers to exploit a crafted packet to cause a denial of service.
5
Where can I find more information on CVE-2013-0250?
More information on CVE-2013-0250 can be found in official security advisories and vulnerability databases.