CVE-2016-7797: High severity ClusterLabs Pacemaker vulnerability
Published Mar 24, 2017
·Updated
Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthenticated connection.
Affected Software
7 affected components
ClusterLabs Pacemaker<=1.1.14
openSUSE Leap=42.2
Opensuse Project Leap=42.1
SUSE Linux Enterprise High Availability=12-sp2
SUSE Linux Enterprise Software Development Kit=12-sp2
redhat Enterprise Linux High Availability=7.0
redhat Enterprise Linux Resilient Storage=7.0
Remediation
Patch Available
Event History
Mar 24, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-7797?
CVE-2016-7797 is categorized as a denial of service vulnerability.
2
How do I fix CVE-2016-7797?
To fix CVE-2016-7797, upgrade to Pacemaker version 1.1.15 or later.
3
Who is affected by CVE-2016-7797?
CVE-2016-7797 affects versions of Pacemaker prior to 1.1.15 when using pacemaker remote.
4
What impact does CVE-2016-7797 have on systems?
CVE-2016-7797 can allow remote attackers to cause a denial of service by disconnecting nodes.
5
Is authentication required to exploit CVE-2016-7797?
No, CVE-2016-7797 can be exploited through unauthenticated connections.