CVE-2009-0115

The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send arbitrary commands to the multipath daemon.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 25%
VendorProductVersion
christophe.varoquimultipath-tools
0.4.8
debiandebian_linux
4.0
debiandebian_linux
5.0
avayaintuity_audix_lx
2.0
avayaintuity_audix_lx
2.0:sp1
avayaintuity_audix_lx
2.0:sp2
avayamessage_networking
3.1
avayamessaging_storage_server
3.0
avayamessaging_storage_server
4.0
avayamessaging_storage_server
5.0
novellopen_enterprise_server
-
opensuseopensuse
10.3 ≤
𝑥
≤ 11.0
juniperctpview
𝑥
< 7.1
juniperctpview
7.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
multipath-tools
bullseye (security)
0.8.5-2+deb11u1
fixed
bullseye
0.8.5-2+deb11u1
fixed
bookworm
0.9.4-3+deb12u1
fixed
sid
0.9.9-1
fixed
trixie
0.9.9-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
multipath-tools
jaunty
not-affected
intrepid
not-affected
hardy
not-affected
gutsy
not-affected
dapper
not-affected
References