VDB
CVE-2011-2147
CVE-2011-2147
PUBLISHED
CVSS 3.5999999046325684 LOW
Openswan 2.2.x does not properly restrict permissions for (1) /var/run/starter.pid, related to starter.c in the IPsec starter, and (2) /var/lock/subsys/ipsec, which allows local users to kill arbitrary processes by writing a PID to a file, or possibly bypass disk quotas by writing arbitrary data to a file, as demonstrated by files with 0666 permissions, a different vulnerability than CVE-2011-1784.
EPSS 0.04% · 13.6th percentile
Risk Scores
CVSS 2.0
3.5999999046325684
EPSS Score
0.04%
13.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| openswan | openswan | 2.2.1, 2.2.0 |
Timeline
- May 20, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- [debian-security] 20110510 World writable pid and lock files. mailing-list
- [debian-security] 20110510 Re: World writable pid and lock files. mailing-list
- openswan-pid-dos(67822) vdb
- [debian-security] 20110510 Re: World writable pid and lock files. mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2011-2147 advisory