← Back

Linbit

linbit

3 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Csync2
csync2
Drbd8
drbd8

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Linbit
2Csync2
Debian Linux
Nov 21, 2024
Dec 30, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the return value GNUTLS_E_WARNING_ALERT_RECEIVED of the gnutls_handshake() function. It neglects to call this function again, as requi...Show more
An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the return value GNUTLS_E_WARNING_ALERT_RECEIVED of the gnutls_handshake() function. It neglects to call this function again, as required by the design of the API.Show less
1Linbit
1Csync2
Nov 21, 2024
Mar 20, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in LINBIT csync2 through 2.0. csync_daemon_session in daemon.c neglects to force a failure of a hello command when the configuration requires use of SSL.
1Linbit
1Drbd8
Nov 21, 2024
Oct 30, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
drbd8 allows local users to bypass intended restrictions for certain actions via netlink packets, similar to CVE-2009-3725.