Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-2526

Опубликовано: 28 июл. 2010
Источник: redhat
CVSS2: 4.8

Описание

The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Cluster Suite 4ASlvm2-clusterAffected
Red Hat Enterprise Linux 5lvm2-clusterAffected
Red Hat Enterprise Linux 6lvm2Affected
Red Hat Enterprise Linux 5lvm2-clusterFixedRHSA-2010:056728.07.2010

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=614248lvm2-cluster: insecurity when communicating between lvm2 and clvmd

4.8 Medium

CVSS2

Связанные уязвимости

ubuntu
около 15 лет назад

The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.

nvd
около 15 лет назад

The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.

debian
около 15 лет назад

The cluster logical volume manager daemon (clvmd) in lvm2-cluster in L ...

github
около 3 лет назад

The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.

oracle-oval
около 15 лет назад

ELSA-2010-0567: lvm2-cluster security update (MODERATE)

4.8 Medium

CVSS2