cvs.linux-ha.orgConfirmation
http://cvs.linux-ha.org/viewcvs/viewcvs.cgi/linux-ha/heartbeat/heartbeat.c?r1=1.513&r2=1.514 CVE-2006-3815
Linux-HA Heartbeat 1.2.3/2.0.x - Insecure Default Permissions on Shared Memory
Record summary
CVE-2006-3815 has a selected CVSS score of 2.1; EIP currently links 1 catalogued exploit.
Description
heartbeat.c in heartbeat before 2.0.6 sets insecure permissions in a shmget call for shared memory, which allows local users to cause an unspecified denial of service via unknown vectors, possibly during a short time window on startup.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBLinux-HA Heartbeat 1.2.3/2.0.x - Insecure Default Permissions on Shared MemoryExploitDB exploitby anonymousNot analyzed1 file
References
Showing 12 of 1621162Third-party advisory
http://secunia.com/advisories/21162 21231Third-party advisory
http://secunia.com/advisories/21231 21240Third-party advisory
http://secunia.com/advisories/21240 21521Third-party advisory
http://secunia.com/advisories/21521 21629Third-party advisory
http://secunia.com/advisories/21629 GLSA-200608-23Vendor advisory
http://security.gentoo.org/glsa/glsa-200608-23.xml 1016602vdb entry
http://securitytracker.com/id?1016602 DSA-1128Vendor advisory
http://www.debian.org/security/2006/dsa-1128 linux-ha.orgConfirmation
http://www.linux-ha.org/_cache/SecurityIssues__sec03.txt mail-archive.comConfirmation
http://www.mail-archive.com/linux-ha-cvs%40lists.linux-ha.org/msg00753.html MDKSA-2006:142Vendor advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2006:142