Vulnerability Name: | CVE-2009-3556 (CCN-55809) | ||||||||||||||||||||||||||||
Assigned: | 2009-10-05 | ||||||||||||||||||||||||||||
Published: | 2010-01-19 | ||||||||||||||||||||||||||||
Updated: | 2023-02-13 | ||||||||||||||||||||||||||||
Summary: | A certain Red Hat configuration step for the qla2xxx driver in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when N_Port ID Virtualization (NPIV) hardware is used, sets world-writable permissions for the (1) vport_create and (2) vport_delete files under /sys/class/scsi_host/, which allows local users to make arbitrary changes to SCSI host attributes by modifying these files. | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 1.9 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:N) 1.4 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
2.6 Low (REDHAT Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||
Vulnerability Type: | CWE-732 | ||||||||||||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2009-3556 Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: VMSA-2010-0009 ESXi utilities and ESX Service Console third party updates Source: CCN Type: RHSA-2010-0046 Important: kernel security and bug fix update Source: CCN Type: SA39920 VMware vMA kernel Multiple Vulnerabilities Source: CCN Type: SA39972 VMware ESXi ntp Mode 7 Request Denial of Service Source: CCN Type: SA39973 VMware ESX Multiple krb5 Vulnerabilities Source: CCN Type: SA39974 VMware ESX GCC libtool Search Path Privilege Escalation Security Issue Source: CCN Type: SA39975 VMware ESX gzip unlzw() Integer Underflow Vulnerability Source: CCN Type: SA39976 VMware vMA OpenSSL CRYPTO_free_all_ex_data() Memory Leak Vulnerability Source: CCN Type: SA39977 VMware vMA Multiple krb5 Vulnerabilities Source: CCN Type: SA39979 VMware vMA GCC libtool Search Path Privilege Escalation Security Issue Source: CCN Type: SA39980 VMware vMA gzip unlzw() Integer Underflow Vulnerability Source: CCN Type: SA39981 VMware vMA sudo Privilege Escalation Security Issues Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: The The Linux Kernel Archives Web site The Linux Kernel Archives Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: BID-37876 Red Hat Linux Kernel 'qla2xxx' DriverSecurity Bypass Vulnerability Source: CCN Type: Red Hat Bugzilla Bug 537177 CVE-2009-3556 kernel: qla2xxx NPIV vport management pseudofiles are world writable Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: XF Type: UNKNOWN kernel-qla2xxx-security-bypass(55809) Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: SUSE Type: SUSE-SA:2010:009 Linux kernel security update Source: SUSE Type: SUSE-SA:2010:019 Linux kernel security update | ||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration RedHat 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |