The (1) SAPDatabase and (2) SAPInstance scripts in OCF Resource Agents (aka resource-agents or cluster-agents) 1.0.3 in Linux-HA place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade rgmanager | Dec 1, 2016 | Oct 20, 2010 |
| Gentoo Linux | — | Upgrade dev-php/PEAR-PEAR.Upgrade x11-apps/xrdb.Upgrade net-analyzer/sflowtool.Upgrade dev-db/unixODBC.Upgrade sys-cluster/rgmanager.Upgrade media-sound/lastfmplayer.Upgrade dev-vcs/gitolite.Upgrade net-misc/rsync.Upgrade media-libs/xine-lib.Upgrade sys-fs/lvm2.Upgrade media-libs/fmod.Upgrade net-misc/vino.Upgrade app-office/gnucash.Upgrade gnome-base/gdm.Upgrade dev-php/PEAR-Mail.Upgrade games-sports/racer-bin.Upgrade sys-apps/shadow.Upgrade app-misc/ca-certificates.Upgrade dev-libs/xmlsec.Upgrade net-misc/mrouted.Upgrade dev-util/oprofile.Upgrade app-admin/syslog-ng.Upgrade net-libs/libsoup.Upgrade net-libs/webkit-gtk.Upgrade dev-util/qt-creator.Upgrade sys-cluster/resource-agents. | Oct 30, 2017 | Oct 20, 2010 |
| Oracle_linux | — | Upgrade rgmanager | Oct 16, 2024 | Oct 20, 2010 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 30, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub