CVE-2013-0281: Medium severity redhat Enterprise Linux vulnerability
A denial of service flaw was found in the way Pacemaker, an advanced, scalable high-availability cluster resource manager for Linux-HA (Heartbeat) and/or Corosync, performed authentication and processing of remote connections in certain circumstances. In general Pacemaker used a blocking socket (without a timeout) to wait for authentication credentials to arrive. When Pacemaker was configured to allow remote Cluster Information Base (CIB) cluster's configuration / cluster's resources management, a remote attacker could use this flaw to cause Pacemaker to block indefinitely (preventing it from serving another requests).
Important Note: In the default configuration of Pacemaker in Red Hat Enterprise Linux 6 the remote CIB management feature / functionality is turned off.
Other sources
Pacemaker 1.1.10, when remote Cluster Information Base (CIB) configuration or resource management is enabled, does not limit the duration of connections to the blocking sockets, which allows remote attackers to cause a denial of service (connection blocking).
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0281?
CVE-2013-0281 is classified as a denial of service vulnerability.
How do I fix CVE-2013-0281?
To fix CVE-2013-0281, update Pacemaker to version 1.1.11 or later.
What software is affected by CVE-2013-0281?
CVE-2013-0281 affects Red Hat Enterprise Linux 6.0 and Pacemaker version 1.1.10.
What happens if CVE-2013-0281 is exploited?
Exploitation of CVE-2013-0281 can lead to a denial of service, impacting the availability of managed resources.
Is CVE-2013-0281 a critical vulnerability?
CVE-2013-0281 is not classified as critical but still poses a significant risk to service availability.