Total vulnerabilities in the database
The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send arbitrary commands to the multipath daemon.
Software | From | Fixed in |
---|---|---|
christophe.varoqui / multipath-tools | 0.4.8 | 0.4.8.x |
fedoraproject / fedora | 10 | 10.x |
fedoraproject / fedora | 9 | 9.x |
debian / debian_linux | 5.0 | 5.0.x |
debian / debian_linux | 4.0 | 4.0.x |
avaya / message_networking | 3.1 | 3.1.x |
avaya / messaging_storage_server | 4.0 | 4.0.x |
avaya / intuity_audix_lx | 2.0-sp1 | 2.0-sp1.x |
avaya / intuity_audix_lx | 2.0-sp2 | 2.0-sp2.x |
avaya / intuity_audix_lx | 2.0 | 2.0.x |
avaya / messaging_storage_server | 3.0 | 3.0.x |
avaya / messaging_storage_server | 5.0 | 5.0.x |
suse / linux_enterprise_server | 9 | 9.x |
opensuse / opensuse | 10.3 | 11.0.x |
suse / linux_enterprise_desktop | 9 | 9.x |
suse / linux_enterprise_server | 10 | 10.x |
juniper / ctpview | - | 7.1 |
juniper / ctpview | 7.1 | 7.1.x |