Vulnerabilities > CVE-2013-0250 - Unspecified vulnerability in Corosync

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
corosync

Summary

The init_nss_hash function in exec/totemcrypto.c in Corosync 2.0 before 2.3 does not properly initialize the HMAC key, which allows remote attackers to cause a denial of service (crash) via a crafted packet. Per: http://cwe.mitre.org/data/definitions/665.html "CWE-665: Improper Initialization"