keepalived Insecure PID Files Insecure File Permissions Vulnerability
BID:47859
Info
keepalived Insecure PID Files Insecure File Permissions Vulnerability
| Bugtraq ID: | 47859 |
| Class: | Design Error |
| CVE: |
CVE-2011-1784 |
| Remote: | No |
| Local: | Yes |
| Published: | May 16 2011 12:00AM |
| Updated: | Apr 13 2015 10:11PM |
| Credit: | helpermn |
| Vulnerable: |
Mandriva Business Server 1 X86 64 Mandriva Business Server 1 Keepalived Keepalived 1.2.2 Gentoo Linux |
| Not Vulnerable: |
Keepalived Keepalived 1.2.3 |
Discussion
keepalived Insecure PID Files Insecure File Permissions Vulnerability
keepalived is prone to an insecure-file-permissions vulnerability.
An attacker may exploit this vulnerability to terminate other processes and deny service to legitimate users.
Keepalived 1.2.2 is vulnerable; other versions may also be affected.
keepalived is prone to an insecure-file-permissions vulnerability.
An attacker may exploit this vulnerability to terminate other processes and deny service to legitimate users.
Keepalived 1.2.2 is vulnerable; other versions may also be affected.
Exploit / POC
keepalived Insecure PID Files Insecure File Permissions Vulnerability
Attackers can exploit the issue using readily available tools.
Attackers can exploit the issue using readily available tools.
References
keepalived Insecure PID Files Insecure File Permissions Vulnerability
References:
References:
- Keepalived Changelog (Keepalived)
- Set correct rights on PID file. (GitHub)
- Vendor Homepage (Keepalived)
- World writable pid and lock files. (Debian)