Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2010-2526


The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.


Published

2010-08-05T13:22:29.450

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.6 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application heinz_mauelshagen lvm2 ≤ 2.02.71 Yes
Application heinz_mauelshagen lvm2 2.02.50 Yes
Application heinz_mauelshagen lvm2 2.02.51 Yes
Application heinz_mauelshagen lvm2 2.02.52 Yes
Application heinz_mauelshagen lvm2 2.02.53 Yes
Application heinz_mauelshagen lvm2 2.02.54 Yes
Application heinz_mauelshagen lvm2 2.02.55 Yes
Application heinz_mauelshagen lvm2 2.02.56 Yes
Application heinz_mauelshagen lvm2 2.02.57 Yes
Application heinz_mauelshagen lvm2 2.02.58 Yes
Application heinz_mauelshagen lvm2 2.02.59 Yes
Application heinz_mauelshagen lvm2 2.02.60 Yes
Application heinz_mauelshagen lvm2 2.02.61 Yes
Application heinz_mauelshagen lvm2 2.02.62 Yes
Application heinz_mauelshagen lvm2 2.02.63 Yes
Application heinz_mauelshagen lvm2 2.02.64 Yes
Application heinz_mauelshagen lvm2 2.02.65 Yes
Application heinz_mauelshagen lvm2 2.02.66 Yes
Application heinz_mauelshagen lvm2 2.02.67 Yes
Application heinz_mauelshagen lvm2 2.02.68 Yes
Application heinz_mauelshagen lvm2 2.02.69 Yes
Application heinz_mauelshagen lvm2 2.02.70 Yes
Application redhat cluster_suite * No
Operating System redhat enterprise_linux 3 No
Operating System redhat enterprise_linux 3.0 No
Operating System redhat enterprise_linux 4 No
Operating System redhat enterprise_linux 4.0 No
Operating System redhat enterprise_linux 5 No

References