Rapid7 Vulnerability & Exploit Database

Red Hat: CVE-2018-16877: CVE-2018-16877 pacemaker: Insufficient local IPC client-server authentication on the client's side can lead to local privesc (Multiple Advisories)

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

Red Hat: CVE-2018-16877: CVE-2018-16877 pacemaker: Insufficient local IPC client-server authentication on the client's side can lead to local privesc (Multiple Advisories)

Severity
5
CVSS
(AV:L/AC:L/Au:N/C:P/I:P/A:P)
Published
04/18/2019
Created
05/29/2019
Added
05/28/2019
Modified
12/15/2023

Description

A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attacker could use this flaw, and combine it with other IPC weaknesses, to achieve local privilege escalation.

Solution(s)

  • redhat-upgrade-pacemaker
  • redhat-upgrade-pacemaker-cli
  • redhat-upgrade-pacemaker-cli-debuginfo
  • redhat-upgrade-pacemaker-cluster-libs
  • redhat-upgrade-pacemaker-cluster-libs-debuginfo
  • redhat-upgrade-pacemaker-cts
  • redhat-upgrade-pacemaker-debuginfo
  • redhat-upgrade-pacemaker-debugsource
  • redhat-upgrade-pacemaker-doc
  • redhat-upgrade-pacemaker-libs
  • redhat-upgrade-pacemaker-libs-debuginfo
  • redhat-upgrade-pacemaker-libs-devel
  • redhat-upgrade-pacemaker-nagios-plugins-metadata
  • redhat-upgrade-pacemaker-remote
  • redhat-upgrade-pacemaker-remote-debuginfo
  • redhat-upgrade-pacemaker-schemas

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;