5
CVSSv2

CVE-2006-3121

Published: 17/08/2006 Updated: 20/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The peel_netstring function in cl_netstring.c in the heartbeat subsystem in High-Availability Linux prior to 1.2.5, and 2.0 prior to 2.0.7, allows remote malicious users to cause a denial of service (crash) via the length parameter in a heartbeat message.

Vulnerable Product Search on Vulmon Subscribe to Product

high availability linux project heartbeat 2.0.2

high availability linux project heartbeat 2.0.3

high availability linux project heartbeat 2.0.4

high availability linux project heartbeat 2.0.5

high availability linux project heartbeat 2.0.6

high availability linux project heartbeat 1.2.3

high availability linux project heartbeat 1.2.4

high availability linux project heartbeat 2.0.1

Vendor Advisories

Yan Rong Ge discovered that heartbeat did not sufficiently verify some packet input data, which could lead to an out-of-boundary memory access A remote attacker could exploit this to crash the daemon (Denial of Service) ...

Exploits

source: wwwsecurityfocuscom/bid/19516/info Linux-HA Heartbeat is prone to a remote denial-of-service vulnerability By successfully exploiting this issue, attackers can crash the master control process This may result in the failure of services that depend on the application's functionality perl -e 'print "###\n2147483647heart attack: ...