Linux-HA Heartbeat Insecure Default Permissions on Shared Memory Vulnerability
BID:19186
CVE-2006-3815 |Info
Linux-HA Heartbeat Insecure Default Permissions on Shared Memory Vulnerability
| Bugtraq ID: | 19186 |
| Class: | Design Error |
| CVE: |
CVE-2006-3815 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 27 2006 12:00AM |
| Updated: | Oct 11 2006 09:44PM |
| Credit: | This vulnerability was reported by the vendor. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.10 sparc Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Linux-HA heartbeat 2.0.5 Linux-HA heartbeat 2.0.4 Linux-HA heartbeat 2.0.3 Linux-HA heartbeat 2.0.2 Linux-HA heartbeat 2.0.1 Linux-HA heartbeat 2.0 Linux-HA heartbeat 1.2.3 Linux-HA heartbeat 1.2.2 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian apt-cacher 0.9.10 |
| Not Vulnerable: |
Linux-HA heartbeat 2.0.6 |
Discussion
Linux-HA Heartbeat Insecure Default Permissions on Shared Memory Vulnerability
Since Linux-HA Heartbeat has insecure default permissions set on shared memory, local attackers may be able to cause a denial of service.
Exploitation would most likely result in a system crash, loss of data, and resource exhaustion, leading to a denial of service if critical files are accessed improperly or overwritten in the attack. Other attacks may be possible as well.
Since Linux-HA Heartbeat has insecure default permissions set on shared memory, local attackers may be able to cause a denial of service.
Exploitation would most likely result in a system crash, loss of data, and resource exhaustion, leading to a denial of service if critical files are accessed improperly or overwritten in the attack. Other attacks may be possible as well.
Exploit / POC
Linux-HA Heartbeat Insecure Default Permissions on Shared Memory Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Linux-HA Heartbeat Insecure Default Permissions on Shared Memory Vulnerability
Solution:
The vendor has released an upgrade that addresses this issue.
Please see the associated advisories for more information.
Linux-HA heartbeat 1.2.3
Linux-HA heartbeat 2.0
Linux-HA heartbeat 2.0.1
Linux-HA heartbeat 2.0.2
Linux-HA heartbeat 2.0.3
Linux-HA heartbeat 2.0.4
Linux-HA heartbeat 2.0.5
Solution:
The vendor has released an upgrade that addresses this issue.
Please see the associated advisories for more information.
Linux-HA heartbeat 1.2.3
-
Mandriva heartbeat-1.2.3-2.3.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva heartbeat-1.2.3-2.3.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva heartbeat-ldirectord-1.2.3-2.3.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva heartbeat-ldirectord-1.2.3-2.3.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva heartbeat-pils-1.2.3-2.3.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva heartbeat-pils-1.2.3-2.3.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva heartbeat-stonith-1.2.3-2.3.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva heartbeat-stonith-1.2.3-2.3.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva lib64heartbeat-pils0-1.2.3-2.3.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva lib64heartbeat-pils0-devel-1.2.3-2.3.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva lib64heartbeat-stonith0-1.2.3-2.3.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva lib64heartbeat-stonith0-devel-1.2.3-2.3.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva lib64heartbeat0-1.2.3-2.3.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva lib64heartbeat0-devel-1.2.3-2.3.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva libheartbeat-pils0-1.2.3-2.3.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva libheartbeat-pils0-devel-1.2.3-2.3.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva libheartbeat-stonith0-1.2.3-2.3.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva libheartbeat-stonith0-devel-1.2.3-2.3.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva libheartbeat0-1.2.3-2.3.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva libheartbeat0-devel-1.2.3-2.3.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads
Linux-HA heartbeat 2.0
-
Linux-HA heartbeat-2.0.7.tar.gz
http://linux-ha.org/download/heartbeat-2.0.7.tar.gz
Linux-HA heartbeat 2.0.1
-
Linux-HA heartbeat-2.0.7.tar.gz
http://linux-ha.org/download/heartbeat-2.0.7.tar.gz
Linux-HA heartbeat 2.0.2
-
Linux-HA heartbeat-2.0.7.tar.gz
http://linux-ha.org/download/heartbeat-2.0.7.tar.gz
Linux-HA heartbeat 2.0.3
-
Linux-HA heartbeat-2.0.7.tar.gz
http://linux-ha.org/download/heartbeat-2.0.7.tar.gz
Linux-HA heartbeat 2.0.4
-
Linux-HA heartbeat-2.0.7.tar.gz
http://linux-ha.org/download/heartbeat-2.0.7.tar.gz
Linux-HA heartbeat 2.0.5
-
Linux-HA heartbeat-2.0.7.tar.gz
http://linux-ha.org/download/heartbeat-2.0.7.tar.gz
References
Linux-HA Heartbeat Insecure Default Permissions on Shared Memory Vulnerability
References:
References:
- 08/13/2006: Security Announcement (Linux-HA)
- Home Page (Linux-HA)
- Linux-HA Heartbeat 'heartbeat.c' Insecure Shared Memory Denial of Service Vulner (FrSIRT)
- Linux-HA: linux-ha/heartbeat/heartbeat.c (Linux-HA)