Vulnerabilities > CVE-2007-4136 - Remote Denial Of Service vulnerability in Redhat Conga 0.10.0

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
redhat
nessus

Summary

The ricci daemon in Red Hat Conga 0.10.0 allows remote attackers to cause a denial of service (loss of new connections) by repeatedly sending data or attempting connections.

Vulnerable Configurations

Part Description Count
Application
Redhat
1

Nessus

  • NASL familyRed Hat Local Security Checks
    NASL idREDHAT-RHSA-2007-0640.NASL
    descriptionUpdated conga packages that correct a security flaw and provide bug fixes and add enhancements are now available. This update has been rated as having moderate security impact by the Red Hat Security Response Team. The Conga package is a web-based administration tool for remote cluster and storage management. A flaw was found in ricci during a code audit. A remote attacker who is able to connect to ricci could cause ricci to temporarily refuse additional connections, a denial of service (CVE-2007-4136). Fixes in this updated package include : * The nodename is now set for manual fencing. * The node log no longer displays in random order. * A bug that prevented a node from responding when a cluster was deleted is now fixed. * A PAM configuration that incorrectly called the deprecated module pam_stack was removed. * A bug that prevented some quorum disk configurations from being accepted is now fixed. * Setting multicast addresses now works properly. * rpm -V on luci no longer fails. * The user interface rendering time for storage interface is now faster. * An error message that incorrectly appeared when rebooting nodes during cluster creation was removed. * Cluster snaps configuration (an unsupported feature) has been removed altogether to prevent user confusion. * A user permission bug resulting from a luci code error is now fixed. * luci and ricci init script return codes are now LSB-compliant. * VG creation on cluster nodes now defaults to
    last seen2020-06-01
    modified2020-06-02
    plugin id63842
    published2013-01-24
    reporterThis script is Copyright (C) 2013-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/63842
    titleRHEL 5 : conga (RHSA-2007:0640)
  • NASL familyScientific Linux Local Security Checks
    NASL idSL_20071107_CONGA_ON_SL5_X.NASL
    descriptionA flaw was found in ricci during a code audit. A remote attacker who is able to connect to ricci could cause ricci to temporarily refuse additional connections, a denial of service (CVE-2007-4136). Fixes in this updated package include : - The nodename is now set for manual fencing. - The node log no longer displays in random order. - A bug that prevented a node from responding when a cluster was deleted is now fixed. - A PAM configuration that incorrectly called the deprecated module pam_stack was removed. - A bug that prevented some quorum disk configurations from being accepted is now fixed. - Setting multicast addresses now works properly. - rpm -V on luci no longer fails. - The user interface rendering time for storage interface is now faster. - An error message that incorrectly appeared when rebooting nodes during cluster creation was removed. - Cluster snaps configuration (an unsupported feature) has been removed altogether to prevent user confusion. - A user permission bug resulting from a luci code error is now fixed. - luci and ricci init script return codes are now LSB-compliant. - VG creation on cluster nodes now defaults to
    last seen2020-06-01
    modified2020-06-02
    plugin id60284
    published2012-08-01
    reporterThis script is Copyright (C) 2012-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/60284
    titleScientific Linux Security Update : conga on SL5.x i386/x86_64

Oval

accepted2013-04-29T04:22:56.073-04:00
classvulnerability
contributors
  • nameAharon Chernin
    organizationSCAP.com, LLC
  • nameDragos Prisaca
    organizationG2, Inc.
definition_extensions
  • commentThe operating system installed on the system is Red Hat Enterprise Linux 5
    ovaloval:org.mitre.oval:def:11414
  • commentThe operating system installed on the system is CentOS Linux 5.x
    ovaloval:org.mitre.oval:def:15802
  • commentOracle Linux 5.x
    ovaloval:org.mitre.oval:def:15459
descriptionThe ricci daemon in Red Hat Conga 0.10.0 allows remote attackers to cause a denial of service (loss of new connections) by repeatedly sending data or attempting connections.
familyunix
idoval:org.mitre.oval:def:9871
statusaccepted
submitted2010-07-09T03:56:16-04:00
titleThe ricci daemon in Red Hat Conga 0.10.0 allows remote attackers to cause a denial of service (loss of new connections) by repeatedly sending data or attempting connections.
version18

Redhat

advisories
bugzilla
id336101
titleCVE-2007-4136 ricci is vulnerable to a connect DoS attack
oval
OR
  • commentRed Hat Enterprise Linux must be installed
    ovaloval:com.redhat.rhba:tst:20070304026
  • AND
    • commentRed Hat Enterprise Linux 5 is installed
      ovaloval:com.redhat.rhba:tst:20070331005
    • OR
      • AND
        • commentluci is earlier than 0:0.10.0-6.el5
          ovaloval:com.redhat.rhsa:tst:20070640001
        • commentluci is signed with Red Hat redhatrelease key
          ovaloval:com.redhat.rhba:tst:20070331002
      • AND
        • commentricci is earlier than 0:0.10.0-6.el5
          ovaloval:com.redhat.rhsa:tst:20070640003
        • commentricci is signed with Red Hat redhatrelease key
          ovaloval:com.redhat.rhba:tst:20070331004
rhsa
idRHSA-2007:0640
released2007-11-08
severityModerate
titleRHSA-2007:0640: conga security, bug fix, and enhancement update (Moderate)
rpms
  • conga-debuginfo-0:0.10.0-6.el5
  • luci-0:0.10.0-6.el5
  • ricci-0:0.10.0-6.el5
  • conga-debuginfo-0:0.11.0-3
  • luci-0:0.11.0-3
  • ricci-0:0.11.0-3