First published: Fri Mar 24 2017(Updated: )
Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthenticated connection.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Pacemaker-libs | <=1.1.14 | |
SUSE Linux | =42.2 | |
openSUSE Leap | =42.1 | |
SUSE Linux Enterprise High Availability | =12-sp2 | |
SUSE Linux Enterprise Software Development Kit | =12-sp2 | |
Red Hat Enterprise Linux High Availability | =7.0 | |
Red Hat Enterprise Linux Resilient Storage | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7797 is categorized as a denial of service vulnerability.
To fix CVE-2016-7797, upgrade to Pacemaker version 1.1.15 or later.
CVE-2016-7797 affects versions of Pacemaker prior to 1.1.15 when using pacemaker remote.
CVE-2016-7797 can allow remote attackers to cause a denial of service by disconnecting nodes.
No, CVE-2016-7797 can be exploited through unauthenticated connections.