The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send arbitrary commands to the multipath daemon.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
History
No history.
Information
Published : 2009-03-30 16:30
Updated : 2024-02-16 20:28
NVD link : CVE-2009-0115
Mitre link : CVE-2009-0115
CVE.ORG link : CVE-2009-0115
JSON object : View
Products Affected
suse
- linux_enterprise_desktop
- linux_enterprise_server
juniper
- ctpview
christophe.varoqui
- multipath-tools
avaya
- message_networking
- messaging_storage_server
- intuity_audix_lx
fedoraproject
- fedora
novell
- open_enterprise_server
opensuse
- opensuse
debian
- debian_linux
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource