CVE-2009-0115
HIGHDevice Mapper <0.4.8 - Command Injection
Title source: llmDescription
The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send arbitrary commands to the multipath daemon.
References (19)
Scores
CVSS v3
7.8
EPSS
0.0008
EPSS Percentile
24.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-732
Status
draft
Affected Products (19)
christophe.varoqui/multipath-tools
fedoraproject/fedora
fedoraproject/fedora
debian/debian_linux
debian/debian_linux
avaya/intuity_audix_lx
avaya/intuity_audix_lx
avaya/intuity_audix_lx
avaya/message_networking
avaya/messaging_storage_server
avaya/messaging_storage_server
avaya/messaging_storage_server
novell/open_enterprise_server
opensuse/opensuse
< 11.0
suse/linux_enterprise_desktop
... and 4 more
Timeline
Published
Mar 30, 2009
Tracked Since
Feb 18, 2026