{"id":"CVE-2009-0115","details":"The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send arbitrary commands to the multipath daemon.","modified":"2026-04-10T03:40:32.612982Z","published":"2009-03-30T16:30:00Z","references":[{"type":"ADVISORY","url":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10691"},{"type":"ADVISORY","url":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705"},{"type":"ADVISORY","url":"http://launchpad.net/bugs/cve/2009-0115"},{"type":"ADVISORY","url":"http://secunia.com/advisories/34418"},{"type":"ADVISORY","url":"http://secunia.com/advisories/34642"},{"type":"ADVISORY","url":"http://secunia.com/advisories/34694"},{"type":"ADVISORY","url":"http://secunia.com/advisories/34710"},{"type":"ADVISORY","url":"http://secunia.com/advisories/34759"},{"type":"ADVISORY","url":"http://secunia.com/advisories/38794"},{"type":"ADVISORY","url":"http://support.avaya.com/elmodocs2/security/ASA-2009-128.htm"},{"type":"ADVISORY","url":"http://www.debian.org/security/2009/dsa-1767"},{"type":"ARTICLE","url":"http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html"},{"type":"ARTICLE","url":"http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.html"},{"type":"ARTICLE","url":"https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00231.html"},{"type":"ARTICLE","url":"https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00236.html"},{"type":"EVIDENCE","url":"http://download.opensuse.org/update/10.3-test/repodata/patch-kpartx-6082.xml"},{"type":"REPORT","url":"http://www.vupen.com/english/advisories/2010/0528"},{"type":"WEB","url":"http://download.opensuse.org/update/10.3-test/repodata/patch-kpartx-6082.xml"},{"type":"WEB","url":"http://lists.vmware.com/pipermail/security-announce/2010/000082.html"},{"type":"WEB","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9214"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}