Pacemaker 1.1.10, when remote Cluster Information Base (CIB) configuration or resource management is enabled, does not limit the duration of connections to the blocking sockets, which allows remote attackers to cause a denial of service (connection blocking).
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "1.1.10+git20130802-1ubuntu2.3",
"binary_name": "libcib3"
},
{
"binary_version": "1.1.10+git20130802-1ubuntu2.3",
"binary_name": "libcib3-dev"
},
{
"binary_version": "1.1.10+git20130802-1ubuntu2.3",
"binary_name": "libcrmcluster4"
},
{
"binary_version": "1.1.10+git20130802-1ubuntu2.3",
"binary_name": "libcrmcluster4-dev"
},
{
"binary_version": "1.1.10+git20130802-1ubuntu2.3",
"binary_name": "libcrmcommon3"
},
{
"binary_version": "1.1.10+git20130802-1ubuntu2.3",
"binary_name": "libcrmcommon3-dev"
},
{
"binary_version": "1.1.10+git20130802-1ubuntu2.3",
"binary_name": "libcrmservice1"
},
{
"binary_version": "1.1.10+git20130802-1ubuntu2.3",
"binary_name": "libcrmservice1-dev"
},
{
"binary_version": "1.1.10+git20130802-1ubuntu2.3",
"binary_name": "liblrmd1"
},
{
"binary_version": "1.1.10+git20130802-1ubuntu2.3",
"binary_name": "liblrmd1-dev"
},
{
"binary_version": "1.1.10+git20130802-1ubuntu2.3",
"binary_name": "libpe-rules2"
},
{
"binary_version": "1.1.10+git20130802-1ubuntu2.3",
"binary_name": "libpe-rules2-dev"
},
{
"binary_version": "1.1.10+git20130802-1ubuntu2.3",
"binary_name": "libpe-status4"
},
{
"binary_version": "1.1.10+git20130802-1ubuntu2.3",
"binary_name": "libpe-status4-dev"
},
{
"binary_version": "1.1.10+git20130802-1ubuntu2.3",
"binary_name": "libpengine4"
},
{
"binary_version": "1.1.10+git20130802-1ubuntu2.3",
"binary_name": "libpengine4-dev"
},
{
"binary_version": "1.1.10+git20130802-1ubuntu2.3",
"binary_name": "libstonithd2"
},
{
"binary_version": "1.1.10+git20130802-1ubuntu2.3",
"binary_name": "libstonithd2-dev"
},
{
"binary_version": "1.1.10+git20130802-1ubuntu2.3",
"binary_name": "libtransitioner2"
},
{
"binary_version": "1.1.10+git20130802-1ubuntu2.3",
"binary_name": "libtransitioner2-dev"
},
{
"binary_version": "1.1.10+git20130802-1ubuntu2.3",
"binary_name": "pacemaker"
},
{
"binary_version": "1.1.10+git20130802-1ubuntu2.3",
"binary_name": "pacemaker-cli-utils"
},
{
"binary_version": "1.1.10+git20130802-1ubuntu2.3",
"binary_name": "pacemaker-dbg"
},
{
"binary_version": "1.1.10+git20130802-1ubuntu2.3",
"binary_name": "pacemaker-dev"
},
{
"binary_version": "1.1.10+git20130802-1ubuntu2.3",
"binary_name": "pacemaker-remote"
}
]
}