rpm package
suse/keepalived&distro=SUSE Linux Enterprise High Availability Extension 15 SP1
pkg:rpm/suse/keepalived&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP1
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-44225 | — | < 2.0.19-150100.3.6.1 | 2.0.19-150100.3.6.1 | Nov 26, 2021 | In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writab | ||
| CVE-2018-19046 | — | < 2.0.19-3.3.1 | 2.0.19-3.3.1 | Nov 8, 2018 | keepalived 2.0.8 didn't check for existing plain files when writing data to a temporary file upon a call to PrintData or PrintStats. If a local attacker had previously created a file with the expected name (e.g., /tmp/keepalived.data or /tmp/keepalived.stats), with read access fo | ||
| CVE-2018-19045 | — | < 2.0.19-3.3.1 | 2.0.19-3.3.1 | Nov 8, 2018 | keepalived 2.0.8 used mode 0666 when creating new temporary files upon a call to PrintData or PrintStats, potentially leaking sensitive information. | ||
| CVE-2018-19044 | — | < 2.0.19-3.3.1 | 2.0.19-3.3.1 | Nov 8, 2018 | keepalived 2.0.8 didn't check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats. This allowed local users to overwrite arbitrary files if fs.protected_symlinks is set to 0, as demonstrated by a symlink from /tmp/keepalived.da |
- CVE-2021-44225Nov 26, 2021affected < 2.0.19-150100.3.6.1fixed 2.0.19-150100.3.6.1
In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writab
- CVE-2018-19046Nov 8, 2018affected < 2.0.19-3.3.1fixed 2.0.19-3.3.1
keepalived 2.0.8 didn't check for existing plain files when writing data to a temporary file upon a call to PrintData or PrintStats. If a local attacker had previously created a file with the expected name (e.g., /tmp/keepalived.data or /tmp/keepalived.stats), with read access fo
- CVE-2018-19045Nov 8, 2018affected < 2.0.19-3.3.1fixed 2.0.19-3.3.1
keepalived 2.0.8 used mode 0666 when creating new temporary files upon a call to PrintData or PrintStats, potentially leaking sensitive information.
- CVE-2018-19044Nov 8, 2018affected < 2.0.19-3.3.1fixed 2.0.19-3.3.1
keepalived 2.0.8 didn't check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats. This allowed local users to overwrite arbitrary files if fs.protected_symlinks is set to 0, as demonstrated by a symlink from /tmp/keepalived.da