Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

CVE-2009-0115

CVE information

Published

15 years ago

Last Modified

2 months ago

CVSSv2.0 Severity

High

CVSSv3.1 Severity

High

Impact Analysis

Description

The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send arbitrary commands to the multipath daemon..

CVSSv2.0 Score

Severity
High
Base Score
7.2/10
Exploit Score
3.9/10
Access Vector
Local
Access Complexity
Low
Authentication Required
None
Impact Score
10/10
Confidentiality Impact
Complete
Availability Impact
Complete
Integrity Impact
Complete

CVSSv3.1 Score

Severity
High
Base Score
7.8/10
Exploit Score
1.8/10
Access Vector
Local
Access Complexity
Low
Privileges Required
Low
Impact Score
5.9/10
Confidentiality Impact
High
Availability Impact
High
Integrity Impact
High
Scope
Unchanged
User Interaction
None

Products Affected

CPE Affected Vulnerable Excluding Edit
cpe:2.3:a:christophe.varoqui:multipath-tools:0.4.8:*:*:*:*:*
  Yes
- -
cpe:2.3:o:fedoraproject:fedora:10:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:fedoraproject:fedora:9:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:avaya:message_networking:3.1:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:avaya:messaging_storage_server:4.0:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:avaya:intuity_audix_lx:2.0:sp1:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:avaya:intuity_audix_lx:2.0:sp2:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:avaya:intuity_audix_lx:2.0:-:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:avaya:messaging_storage_server:3.0:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:avaya:messaging_storage_server:5.0:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:suse:linux_enterprise_server:9:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:opensuse:opensuse:*:*:*:*:*:*:*:*
  Yes
10.3 -
cpe:2.3:o:suse:linux_enterprise_desktop:9:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:suse:linux_enterprise_server:10:-:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:novell:open_enterprise_server:-:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:juniper:ctpview:*:*:*:*:*:*:*:*
  Yes
- 7.1
cpe:2.3:a:juniper:ctpview:7.1:-:*:*:*:*:*:*
  Yes
- -