Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!Close

CVE-2013-0250

Published: 6 June 2014

The init_nss_hash function in exec/totemcrypto.c in Corosync 2.0 before 2.3 does not properly initialize the HMAC key, which allows remote attackers to cause a denial of service (crash) via a crafted packet.

Priority

Medium

Status

Package Release Status
corosync
Launchpad, Ubuntu, Debian
upstream Needs triage

hardy Does not exist

lucid Not vulnerable
(code-not-present)
oneiric Not vulnerable
(code-not-present)
precise Not vulnerable
(code-not-present)
quantal Not vulnerable
(code-not-present)
raring Not vulnerable
(code-not-present)
Patches:
upstream: https://github.com/corosync/corosync/commit/b3f456a8ceefac6e9f2e9acc2ea0c159d412b595