Tracker / CVE-2009-0115
CVE-2009-0115
High 7.8
The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send arbitrary commands to the multipath daemon.
Affected products and versions
| avaya | intuity_audix_lx |
|---|---|
| avaya | message_networking |
| avaya | messaging_storage_server |
| christophe.varoqui | multipath-tools |
| debian | debian_linux |
| fedoraproject | fedora |
| juniper | ctpview |
| juniper | ctpview · … → 7.1 |
| novell | open_enterprise_server |
| opensuse | opensuse · 10.3 → 11.0 |
| suse | linux_enterprise_desktop |
| suse | linux_enterprise_server |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.