VDB
CVE-2009-3556
CVE-2009-3556
PUBLISHED
CVSS 1.899999976158142 LOW
A certain Red Hat configuration step for the qla2xxx driver in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when N_Port ID Virtualization (NPIV) hardware is used, sets world-writable permissions for the (1) vport_create and (2) vport_delete files under /sys/class/scsi_host/, which allows local users to make arbitrary changes to SCSI host attributes by modifying these files.
EPSS 0.38% · 29.7th percentile
Risk Scores
CVSS 2.0
1.899999976158142
EPSS Score
0.38%
29.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redhat | enterprise_linux | 5 |
| n/a | n/a | n/a |
| linux | linux_kernel | 2.6.18 |
Timeline
- Jan 27, 2010 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Oct 28, 2022 EPSS Score
- Dec 20, 2022 EPSS Score
- Feb 11, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 6, 2023 EPSS Score
- May 29, 2023 EPSS Score
References
- [oss-security] 20100120 CVE-2009-3556 kernel: qla2xxx NPIV vport management pseudofiles are world writable mailing-list
- kernel-qla2xxx-security-bypass(55809) vdb
- SUSE-SA:2010:019 vendor-advisory
- RHSA-2010:0095 vendor-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=537177 url
- http://support.avaya.com/css/P8/documents/100073666 url
- oval:org.mitre.oval:def:9738 vdb
- oval:org.mitre.oval:def:6744 vdb
- RHSA-2010:0046 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-3556 advisory
- https://access.redhat.com/errata/RHSA-2010:0046 url
- https://access.redhat.com/security/cve/CVE-2009-3556 url