VDB
BDU%3A2023-09098
BDU%3A2023-09098
PUBLISHED
CVSS 6.800000190734863 MEDIUM
Уязвимость программного обеспечения управления драйверами для организации многопутевого доступа Multipath-tools, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
6.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ООО «РусБИТех-Астра», Сообщество свободного программного обеспечения, АО «ИВК», АО "НППКТ", OpenSVC | Astra Linux Special Edition (запись в едином реестре российских программ №369), Debian GNU/Linux, Альт 8 СП (запись в едином реестре российских программ №4305), ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913), multipath-tools |
Timeline
- Dec 26, 2023 CVE Published
- Sep 24, 2024 CVE Updated
References
- http://packetstormsecurity.com/files/169611/Leeloo-Multipath-Authorization-Bypass-Symlink-Attack.html url
- http://packetstormsecurity.com/files/170176/snap-confine-must_mkdir_and_open_with_perms-Race-Condition.html url
- http://seclists.org/fulldisclosure/2022/Dec/4 url
- http://seclists.org/fulldisclosure/2022/Oct/25 url
- http://www.openwall.com/lists/oss-security/2022/10/24/2 url
- http://www.openwall.com/lists/oss-security/2022/11/30/2 url
- https://bugzilla.suse.com/show_bug.cgi?id=1202739 url
- https://github.com/opensvc/multipath-tools/commit/2a1ff3154c1d5de423c303ca3bc9ed9727b4e523 url
- https://github.com/opensvc/multipath-tools/commit/994811a29332161ec150f1d9822ff460cfc0f316 url
- https://github.com/opensvc/multipath-tools/commit/c4912a639b7ff527aa11d665944594926ff94a7a url
- https://github.com/opensvc/multipath-tools/commit/cb57b930fa690ab79b3904846634681685e3470f url
- https://github.com/opensvc/multipath-tools/commit/d139bcf0842bc0a16beab86e1349ed65b150bf0c url
- https://github.com/opensvc/multipath-tools/commit/f812466f68b8e020818c6454d7b7a7e278bc99f6 url
- https://github.com/opensvc/multipath-tools/releases/tag/0.9.2 url
- https://lists.debian.org/debian-lts-announce/2022/12/msg00037.html url
- https://nvd.nist.gov/vuln/detail/CVE-2022-41973 url
- https://www.qualys.com/2022/10/24/leeloo-multipath/leeloo-multipath.txt url
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.7/ url
- https://altsp.su/obnovleniya-bezopasnosti/ url
- https://github.com/opensvc/multipath-tools/pull/46 advisory
…and 3 more