Vulnerability Description
The init_nss_hash function in exec/totemcrypto.c in Corosync 2.0 before 2.3 does not properly initialize the HMAC key, which allows remote attackers to cause a denial of service (crash) via a crafted packet.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Corosync | Corosync | 2.0.0 |
References
- http://seclists.org/oss-sec/2013/q1/212
- http://seclists.org/oss-sec/2013/q1/213
- http://seclists.org/oss-sec/2013/q1/214
- http://secunia.com/advisories/52037
- https://github.com/corosync/corosync/commit/b3f456a8ceefac6e9f2e9acc2ea0c159d412ExploitPatch
- http://seclists.org/oss-sec/2013/q1/212
- http://seclists.org/oss-sec/2013/q1/213
- http://seclists.org/oss-sec/2013/q1/214
- http://secunia.com/advisories/52037
- https://github.com/corosync/corosync/commit/b3f456a8ceefac6e9f2e9acc2ea0c159d412ExploitPatch
FAQ
What is CVE-2013-0250?
CVE-2013-0250 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The init_nss_hash function in exec/totemcrypto.c in Corosync 2.0 before 2.3 does not properly initialize the HMAC key, which allows remote attackers to cause a denial of service (crash) via a crafted ...
How severe is CVE-2013-0250?
CVE-2013-0250 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-0250?
Check the references section above for vendor advisories and patch information. Affected products include: Corosync Corosync.