Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-1000201

Опубликовано: 14 июл. 2017
Источник: redhat
CVSS3: 5.5

Описание

The tcmu-runner daemon in tcmu-runner version 1.0.5 to 1.2.0 is vulnerable to a local denial of service attack

A NULL pointer dereference flaw was found in the UnregisterHandler method implemented in the tcmu-runner daemon. A local, non-root user with access to the D-Bus system bus could call UnregisterHandler method with non-existing tcmu handler as paramater to trigger DoS.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 2tcmu-runnerAffected
Red Hat Gluster Storage 3.3 for RHEL 7tcmu-runnerFixedRHSA-2017:327729.11.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1487247tcmu-runner: UnregisterHandler dbus method in tcmu-runner daemon for non-existing handler causes DoS

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
почти 9 лет назад

The tcmu-runner daemon in tcmu-runner version 1.0.5 to 1.2.0 is vulnerable to a local denial of service attack

CVSS3: 5.5
github
больше 4 лет назад

The tcmu-runner daemon in tcmu-runner version 1.0.5 to 1.2.0 is vulnerable to a local denial of service attack

5.5 Medium

CVSS3

Уязвимость CVE-2017-1000201