First published: Fri May 09 2014(Updated: )
Apache Karaf before 4.0.10 enables a shutdown port on the loopback interface, which allows local users to cause a denial of service (shutdown) by sending a shutdown command to all listening high ports.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Karaf | <4.0.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0219 is classified with a severity that indicates a denial of service risk due to its ability to allow local users to shutdown the service.
To fix CVE-2014-0219, upgrade Apache Karaf to version 4.0.10 or later.
Apache Karaf versions prior to 4.0.10 are affected by CVE-2014-0219.
CVE-2014-0219 enables a local denial of service attack by allowing unauthorized shutdown commands to be executed.
As a workaround for CVE-2014-0219, you can restrict access to the shutdown port by modifying network configuration to limit local access.