CVE-2006-3815

heartbeat.c in heartbeat before 2.0.6 sets insecure permissions in a shmget call for shared memory, which allows local users to cause an unspecified denial of service via unknown vectors, possibly during a short time window on startup.
References
Link Resource
http://cvs.linux-ha.org/viewcvs/viewcvs.cgi/linux-ha/heartbeat/heartbeat.c?r1=1.513&r2=1.514 Patch
http://secunia.com/advisories/21162 Vendor Advisory
http://secunia.com/advisories/21231 Vendor Advisory
http://secunia.com/advisories/21240 Vendor Advisory
http://secunia.com/advisories/21521 Vendor Advisory
http://secunia.com/advisories/21629 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200608-23.xml
http://securitytracker.com/id?1016602
http://www.debian.org/security/2006/dsa-1128
http://www.linux-ha.org/_cache/SecurityIssues__sec03.txt
http://www.mail-archive.com/linux-ha-cvs%40lists.linux-ha.org/msg00753.html Patch
http://www.mandriva.com/security/advisories?name=MDKSA-2006:142
http://www.securityfocus.com/bid/19186
http://www.ubuntu.com/usn/usn-326-1
http://www.vupen.com/english/advisories/2006/2994 Vendor Advisory
http://cvs.linux-ha.org/viewcvs/viewcvs.cgi/linux-ha/heartbeat/heartbeat.c?r1=1.513&r2=1.514 Patch
http://secunia.com/advisories/21162 Vendor Advisory
http://secunia.com/advisories/21231 Vendor Advisory
http://secunia.com/advisories/21240 Vendor Advisory
http://secunia.com/advisories/21521 Vendor Advisory
http://secunia.com/advisories/21629 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200608-23.xml
http://securitytracker.com/id?1016602
http://www.debian.org/security/2006/dsa-1128
http://www.linux-ha.org/_cache/SecurityIssues__sec03.txt
http://www.mail-archive.com/linux-ha-cvs%40lists.linux-ha.org/msg00753.html Patch
http://www.mandriva.com/security/advisories?name=MDKSA-2006:142
http://www.securityfocus.com/bid/19186
http://www.ubuntu.com/usn/usn-326-1
http://www.vupen.com/english/advisories/2006/2994 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:linux-ha:heartbeat:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:14

Type Values Removed Values Added
References () http://cvs.linux-ha.org/viewcvs/viewcvs.cgi/linux-ha/heartbeat/heartbeat.c?r1=1.513&r2=1.514 - Patch () http://cvs.linux-ha.org/viewcvs/viewcvs.cgi/linux-ha/heartbeat/heartbeat.c?r1=1.513&r2=1.514 - Patch
References () http://secunia.com/advisories/21162 - Vendor Advisory () http://secunia.com/advisories/21162 - Vendor Advisory
References () http://secunia.com/advisories/21231 - Vendor Advisory () http://secunia.com/advisories/21231 - Vendor Advisory
References () http://secunia.com/advisories/21240 - Vendor Advisory () http://secunia.com/advisories/21240 - Vendor Advisory
References () http://secunia.com/advisories/21521 - Vendor Advisory () http://secunia.com/advisories/21521 - Vendor Advisory
References () http://secunia.com/advisories/21629 - Vendor Advisory () http://secunia.com/advisories/21629 - Vendor Advisory
References () http://security.gentoo.org/glsa/glsa-200608-23.xml - () http://security.gentoo.org/glsa/glsa-200608-23.xml -
References () http://securitytracker.com/id?1016602 - () http://securitytracker.com/id?1016602 -
References () http://www.debian.org/security/2006/dsa-1128 - () http://www.debian.org/security/2006/dsa-1128 -
References () http://www.linux-ha.org/_cache/SecurityIssues__sec03.txt - () http://www.linux-ha.org/_cache/SecurityIssues__sec03.txt -
References () http://www.mail-archive.com/linux-ha-cvs%40lists.linux-ha.org/msg00753.html - Patch () http://www.mail-archive.com/linux-ha-cvs%40lists.linux-ha.org/msg00753.html - Patch
References () http://www.mandriva.com/security/advisories?name=MDKSA-2006:142 - () http://www.mandriva.com/security/advisories?name=MDKSA-2006:142 -
References () http://www.securityfocus.com/bid/19186 - () http://www.securityfocus.com/bid/19186 -
References () http://www.ubuntu.com/usn/usn-326-1 - () http://www.ubuntu.com/usn/usn-326-1 -
References () http://www.vupen.com/english/advisories/2006/2994 - Vendor Advisory () http://www.vupen.com/english/advisories/2006/2994 - Vendor Advisory

Information

Published : 2006-07-25 13:22

Updated : 2024-11-21 00:14


NVD link : CVE-2006-3815

Mitre link : CVE-2006-3815

CVE.ORG link : CVE-2006-3815


JSON object : View

Products Affected

linux-ha

  • heartbeat
CWE
CWE-264

Permissions, Privileges, and Access Controls