CVE-2009-0115

HIGH

Device Mapper <0.4.8 - Command Injection

Title source: llm

Description

The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send arbitrary commands to the multipath daemon.

References (19)

Scores

CVSS v3 7.8
EPSS 0.0008
EPSS Percentile 24.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-732
Status draft

Affected Products (19)

christophe.varoqui/multipath-tools
fedoraproject/fedora
fedoraproject/fedora
debian/debian_linux
debian/debian_linux
avaya/intuity_audix_lx
avaya/intuity_audix_lx
avaya/intuity_audix_lx
avaya/message_networking
avaya/messaging_storage_server
avaya/messaging_storage_server
avaya/messaging_storage_server
novell/open_enterprise_server
opensuse/opensuse < 11.0
suse/linux_enterprise_desktop
... and 4 more

Timeline

Published Mar 30, 2009
Tracked Since Feb 18, 2026