5.5

CVE-2018-16878

A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processes can lead to DoS
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Clusterlabs ≫ Pacemaker Version <= 2.0.1
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.10
Canonical ≫ Ubuntu Linux Version 19.04
Fedoraproject ≫ Fedora Version 28
Fedoraproject ≫ Fedora Version 29
Fedoraproject ≫ Fedora Version 30
Debian ≫ Debian Linux Version 9.0
Opensuse ≫ Leap Version 15.0
Opensuse ≫ Leap Version 42.3
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Aus Version 8.2
Redhat ≫ Enterprise Linux Aus Version 8.4
Redhat ≫ Enterprise Linux Aus Version 8.6
Redhat ≫ Enterprise Linux Eus Version 8.1
Redhat ≫ Enterprise Linux Eus Version 8.2
Redhat ≫ Enterprise Linux Eus Version 8.4
Redhat ≫ Enterprise Linux Eus Version 8.6
Redhat ≫ Enterprise Linux Tus Version 8.2
Redhat ≫ Enterprise Linux Tus Version 8.4
Redhat ≫ Enterprise Linux Tus Version 8.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.44% 0.348
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat 6.2 2.5 3.6
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00012.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00034.html
Third Party Advisory
Mailing List
https://access.redhat.com/errata/RHSA-2019:1278
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1279
Third Party Advisory
https://github.com/ClusterLabs/pacemaker/pull/1749
Patch
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2021/01/msg00007.html
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3GCWFO7GL6MBU6C4BGFO3P6L77DIBBF3/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FY4M4RMIG2POKC6OOFQODGKPRYXHET2F/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HR6QUYGML735EI3HEEHYRDW7EG73BUH2/
https://security.gentoo.org/glsa/202309-09
https://usn.ubuntu.com/3952-1/
Third Party Advisory
http://www.securityfocus.com/bid/108039
Broken Link
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16878
Patch
Third Party Advisory
Issue Tracking