VYPR

rpm package

opensuse/keepalived&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/keepalived&distro=openSUSE%20Tumbleweed

Vulnerabilities (5)

  • CVE-2024-41184CriJul 18, 2024
    affected < 2.3.1+git59.b6681f98-1.1fixed 2.3.1+git59.b6681f98-1.1

    In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: this CVE Record might not be worthwhile because an empty ipset name must be configured by the user.

  • CVE-2021-44225Nov 26, 2021
    affected < 2.2.7-1.1fixed 2.2.7-1.1

    In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writab

  • CVE-2018-19046Nov 8, 2018
    affected < 2.2.2-4.2fixed 2.2.2-4.2

    keepalived 2.0.8 didn't check for existing plain files when writing data to a temporary file upon a call to PrintData or PrintStats. If a local attacker had previously created a file with the expected name (e.g., /tmp/keepalived.data or /tmp/keepalived.stats), with read access fo

  • CVE-2018-19045Nov 8, 2018
    affected < 2.2.2-4.2fixed 2.2.2-4.2

    keepalived 2.0.8 used mode 0666 when creating new temporary files upon a call to PrintData or PrintStats, potentially leaking sensitive information.

  • CVE-2018-19044Nov 8, 2018
    affected < 2.2.2-4.2fixed 2.2.2-4.2

    keepalived 2.0.8 didn't check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats. This allowed local users to overwrite arbitrary files if fs.protected_symlinks is set to 0, as demonstrated by a symlink from /tmp/keepalived.da