From 7f0ccc917c7abe6223784c703d86cd14755691fb Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Sat, 3 Jul 2021 22:39:47 +0100 Subject: gentoo resync : 03.07.2021 --- metadata/glsa/glsa-202107-01.xml | 52 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 52 insertions(+) create mode 100644 metadata/glsa/glsa-202107-01.xml (limited to 'metadata/glsa/glsa-202107-01.xml') diff --git a/metadata/glsa/glsa-202107-01.xml b/metadata/glsa/glsa-202107-01.xml new file mode 100644 index 000000000000..032f9797ab47 --- /dev/null +++ b/metadata/glsa/glsa-202107-01.xml @@ -0,0 +1,52 @@ + + + + corosync: Denial of service + A vulnerability in corosync could lead to a Denial of Service + condition. + + corosync + 2021-07-03 + 2021-07-03 + 658354 + remote + + + 3.0.4 + 3.0.4 + + + +

The Corosync Cluster Engine is a Group Communication System with + additional features for implementing high availability within + applications. +

+
+ +

It was discovered that corosync allowed an unauthenticated user to cause + a Denial of Service by application crash. +

+
+ +

A remote attacker could send a malicious crafted packet, possibly + resulting in a Denial of Service condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All corosync users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=sys-cluster/corosync-3.0.4" + + +
+ + CVE-2018-1084 + + whissi + whissi +
-- cgit v1.2.3