The peel_netstring function in cl_netstring.c in the heartbeat subsystem in High-Availability Linux before 1.2.5, and 2.0 before 2.0.7, allows remote attackers to cause a denial of service (crash) via the length parameter in a heartbeat message.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade heartbeat | Jul 30, 2024 | Aug 17, 2006 |
| Gentoo Linux | — | Upgrade sys-cluster/heartbeat. | Oct 30, 2017 | Aug 16, 2006 |
| Suse | — | Upgrade ocfs2-toolsUpgrade heartbeat-cmpiUpgrade heartbeatUpgrade heartbeat-stonithUpgrade heartbeat-ldirectordUpgrade drbdUpgrade ocfs2consoleUpgrade heartbeat-pils | Dec 12, 2013 | Aug 16, 2006 |
| Ubuntu | — | Upgrade heartbeat | Nov 8, 2024 | Aug 17, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub