VYPR

rpm package

suse/keepalived&distro=SUSE Linux Enterprise High Availability Extension 15 SP1

pkg:rpm/suse/keepalived&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP1

Vulnerabilities (4)

  • CVE-2021-44225Nov 26, 2021
    affected < 2.0.19-150100.3.6.1fixed 2.0.19-150100.3.6.1

    In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writab

  • CVE-2018-19046Nov 8, 2018
    affected < 2.0.19-3.3.1fixed 2.0.19-3.3.1

    keepalived 2.0.8 didn't check for existing plain files when writing data to a temporary file upon a call to PrintData or PrintStats. If a local attacker had previously created a file with the expected name (e.g., /tmp/keepalived.data or /tmp/keepalived.stats), with read access fo

  • CVE-2018-19045Nov 8, 2018
    affected < 2.0.19-3.3.1fixed 2.0.19-3.3.1

    keepalived 2.0.8 used mode 0666 when creating new temporary files upon a call to PrintData or PrintStats, potentially leaking sensitive information.

  • CVE-2018-19044Nov 8, 2018
    affected < 2.0.19-3.3.1fixed 2.0.19-3.3.1

    keepalived 2.0.8 didn't check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats. This allowed local users to overwrite arbitrary files if fs.protected_symlinks is set to 0, as demonstrated by a symlink from /tmp/keepalived.da