HIGH · 7.8

CVE-2009-0115

The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating system...

Vulnerability Description

The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send arbitrary commands to the multipath daemon.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Christophe.VaroquiMultipath-Tools0.4.8
FedoraprojectFedora9
DebianDebian Linux4.0
AvayaIntuity Audix Lx2.0
AvayaMessage Networking3.1
AvayaMessaging Storage Server3.0
NovellOpen Enterprise Server-
OpensuseOpensuse>= 10.3, <= 11.0
SuseLinux Enterprise Desktop9
SuseLinux Enterprise Server9
JuniperCtpview< 7.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-0115?

CVE-2009-0115 is a vulnerability with a CVSS score of 7.8 (HIGH). The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating system...

How severe is CVE-2009-0115?

CVE-2009-0115 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-0115?

Check the references section above for vendor advisories and patch information. Affected products include: Christophe.Varoqui Multipath-Tools, Fedoraproject Fedora, Debian Debian Linux, Avaya Intuity Audix Lx, Avaya Message Networking.