rpm package
opensuse/keepalived&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/keepalived&distro=openSUSE%20Tumbleweed
Vulnerabilities (5)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-41184 | Cri | 9.8 | < 2.3.1+git59.b6681f98-1.1 | 2.3.1+git59.b6681f98-1.1 | Jul 18, 2024 | In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: this CVE Record might not be worthwhile because an empty ipset name must be configured by the user. | |
| CVE-2021-44225 | — | < 2.2.7-1.1 | 2.2.7-1.1 | Nov 26, 2021 | In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writab | ||
| CVE-2018-19046 | — | < 2.2.2-4.2 | 2.2.2-4.2 | Nov 8, 2018 | keepalived 2.0.8 didn't check for existing plain files when writing data to a temporary file upon a call to PrintData or PrintStats. If a local attacker had previously created a file with the expected name (e.g., /tmp/keepalived.data or /tmp/keepalived.stats), with read access fo | ||
| CVE-2018-19045 | — | < 2.2.2-4.2 | 2.2.2-4.2 | Nov 8, 2018 | keepalived 2.0.8 used mode 0666 when creating new temporary files upon a call to PrintData or PrintStats, potentially leaking sensitive information. | ||
| CVE-2018-19044 | — | < 2.2.2-4.2 | 2.2.2-4.2 | Nov 8, 2018 | keepalived 2.0.8 didn't check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats. This allowed local users to overwrite arbitrary files if fs.protected_symlinks is set to 0, as demonstrated by a symlink from /tmp/keepalived.da |
- affected < 2.3.1+git59.b6681f98-1.1fixed 2.3.1+git59.b6681f98-1.1
In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: this CVE Record might not be worthwhile because an empty ipset name must be configured by the user.
- CVE-2021-44225Nov 26, 2021affected < 2.2.7-1.1fixed 2.2.7-1.1
In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writab
- CVE-2018-19046Nov 8, 2018affected < 2.2.2-4.2fixed 2.2.2-4.2
keepalived 2.0.8 didn't check for existing plain files when writing data to a temporary file upon a call to PrintData or PrintStats. If a local attacker had previously created a file with the expected name (e.g., /tmp/keepalived.data or /tmp/keepalived.stats), with read access fo
- CVE-2018-19045Nov 8, 2018affected < 2.2.2-4.2fixed 2.2.2-4.2
keepalived 2.0.8 used mode 0666 when creating new temporary files upon a call to PrintData or PrintStats, potentially leaking sensitive information.
- CVE-2018-19044Nov 8, 2018affected < 2.2.2-4.2fixed 2.2.2-4.2
keepalived 2.0.8 didn't check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats. This allowed local users to overwrite arbitrary files if fs.protected_symlinks is set to 0, as demonstrated by a symlink from /tmp/keepalived.da