The cluster logical volume manager daemon (clvmd) in lvm2-cluster in...
Vulnerability Description
The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-2526
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.ubuntu.com/usn/USN-1001-1
- https://www.redhat.com/archives/linux-lvm/2010-July/msg00083.html
- http://secunia.com/advisories/40759
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60809
- https://rhn.redhat.com/errata/RHSA-2010-0568.html
- https://rhn.redhat.com/errata/RHSA-2010-0567.html
- http://securitytracker.com/id?1024258
- https://bugzilla.redhat.com/show_bug.cgi?id=614248
- http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html
- http://www.osvdb.org/66753
- http://www.vupen.com/english/advisories/2010/1944
Affected Vendor
heinz mauelshagen
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.