|
OpenBSD contains a flaw that may allow a remote denial of service. The issue is triggered when the CARP implementation fails to include all fields contained in the 'carp_header' structure when calculating the SHA1 HMAC hash of the packet in the 'carp_proto_input_c' function, allowing an attacker to force all CARP nodes to assume the backup role, resulting in a denial of service.
|