CVE-2009-3939
7.1
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Exploitability: 1.8 / Impact: 5.2
Source: NVD
Description
The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file.
Affected (29)
Products: Linux: Linux Kernel · Redhat: Enterprise Linux Desktop, Enterprise Linux Eus, Enterprise Linux Server, Enterprise Linux Workstation, Virtualization · Canonical: Ubuntu Linux · +4 more
Show all products
Linux: Linux Kernel · Redhat: Enterprise Linux Desktop, Enterprise Linux Eus, Enterprise Linux Server, Enterprise Linux Workstation, Virtualization · Canonical: Ubuntu Linux · Debian: Debian Linux · Avaya: Aura Application Enablement Services, Aura Communication Manager, Aura Session Manager, Aura Sip Enablement Services, Aura System Manager, Aura System Platform, Voice Portal · Opensuse: Opensuse · Suse: Linux Enterprise Desktop, Linux Enterprise Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.6.31.6 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.0 | |
| Version 5.4 | |
| Version 5.0 | |
| Version 5.0 | |
| Version 5 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.06 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.2.1 | |
| Version 5.2 | |
| Version 1.1 | |
| Version 5.2 | |
| Version 5.2 | |
| Version 1.1 | |
| Version 5.0 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.0 | |
| Version 10 sp3 | |
| Version 10 sp3 |
References (46)
Source: cve@mitre.org
Mailing List
Source: cve@mitre.org
Mailing List
Source: cve@mitre.org
Mailing List
Source: cve@mitre.org
Mailing List
Source: cve@mitre.org
Mailing List
Source: cve@mitre.org
Mailing List
Source: cve@mitre.org
Mailing List
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.