Jump to content

Advisories MDKSA-2006:142: Updated heartbeat packages fix vulnerability


paul
 Share

Recommended Posts

Two vulnerabilities in heartbeat prior to 2.0.6 was discovered by Yan

Rong Ge. The first is that heartbeat would set insecure permissions in

an shmget call for shared memory, allowing a local attacker to cause an

unspecified denial of service via unknown vectors (CVE-2006-3815).

 

The second is a remote vulnerability that could allow allow the master

control process to read invalid memory due to a specially crafted

heartbeat message and die of a SEGV, all prior to any authentication

(CVE-2006-3121).

 

Updated packages have been patched to correct these issues.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...