Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2hvv-h4pw-wcm2

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.

The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.

EPSS

Процентиль: 26%
0.00087
Низкий

Дефекты

CWE-287

Связанные уязвимости

ubuntu
почти 15 лет назад

The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.

redhat
почти 15 лет назад

The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.

nvd
почти 15 лет назад

The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.

debian
почти 15 лет назад

The cluster logical volume manager daemon (clvmd) in lvm2-cluster in L ...

oracle-oval
почти 15 лет назад

ELSA-2010-0567: lvm2-cluster security update (MODERATE)

EPSS

Процентиль: 26%
0.00087
Низкий

Дефекты

CWE-287