VDB
CVE-2009-3556
CVE-2009-3556
PUBLISHED
CVSS 1.899999976158142 LOW
A certain Red Hat configuration step for the qla2xxx driver in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when N_Port ID Virtualization (NPIV) hardware is used, sets world-writable permissions for the (1) vport_create and (2) vport_delete files under /sys/class/scsi_host/, which allows local users to make arbitrary changes to SCSI host attributes by modifying these files.
EPSS 0.03% · 10.3th percentile
Risk Scores
CVSS 2.0
1.899999976158142
EPSS Score
0.03%
10.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redhat | enterprise_linux | 5 |
| n/a | n/a | n/a |
| linux | linux_kernel | 2.6.18 |
Exploit Intelligence
- [oss-security] 20100120 CVE-2009-3556 kernel: qla2xxx NPIV vport management pseudofiles are world writable (circl)
- https://bugzilla.redhat.com/show_bug.cgi?id=537177 (circl)
- http://support.avaya.com/css/P8/documents/100073666 (circl)
- oval:org.mitre.oval:def:9738 (circl)
- kernel-qla2xxx-security-bypass(55809) (circl)
- SUSE-SA:2010:019 (circl)
- oval:org.mitre.oval:def:6744 (circl)
- RHSA-2010:0095 (circl)
- RHSA-2010:0046 (circl)
Timeline
- Jan 27, 2010 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
References
- [oss-security] 20100120 CVE-2009-3556 kernel: qla2xxx NPIV vport management pseudofiles are world writable mailing-list
- https://bugzilla.redhat.com/show_bug.cgi?id=537177 url
- http://support.avaya.com/css/P8/documents/100073666 url
- oval:org.mitre.oval:def:9738 vdb
- kernel-qla2xxx-security-bypass(55809) vdb
- SUSE-SA:2010:019 vendor-advisory
- oval:org.mitre.oval:def:6744 vdb
- RHSA-2010:0095 vendor-advisory
- RHSA-2010:0046 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-3556 advisory
- https://access.redhat.com/errata/RHSA-2010:0046 url
- https://access.redhat.com/security/cve/CVE-2009-3556 url