← Back

CVE-2009-0115

nvd nist
Published: Mar 30, 2009Modified: Apr 23, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send arbitrary commands to the multipath daemon.

Affected (19)

Show all products
Multipath Tools
1 product
Fedora
1 product
Debian Linux
3 products
Intuity Audix Lx
Message Networking
Messaging Storage Server
1 product
Open Enterprise Server
1 product
Opensuse
2 products
Linux Enterprise Desktop
Linux Enterprise Server
1 product
Ctpview
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 0.4.8
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 10
Version 9
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 4.0
Version 5.0
Configuration D
7 vulnerable
Vulnerable SoftwareAffected Versions
Avaya
Version 2.0
Version 2.0 sp1
Version 2.0 sp2
Version 3.1
Avaya
Version 3.0
Version 4.0
Version 5.0
Configuration E
5 vulnerable
Vulnerable SoftwareAffected Versions
All versions
From 10.3 to 11.0
Version 9
Suse
Version 10
Version 9
Configuration F
2 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Before 7.1
Version 7.1

References (38)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Broken LinkVendor Advisory
Source: cve@mitre.org
Broken LinkVendor Advisory
Source: cve@mitre.org
Broken LinkVendor Advisory
Source: cve@mitre.org
Broken LinkVendor Advisory
Source: cve@mitre.org
Broken LinkVendor Advisory
Source: cve@mitre.org
Broken LinkVendor Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkExploit
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List

Timeline

No history available yet.