heartbeat.c in heartbeat before 2.0.6 sets insecure permissions in a shmget call for shared memory, which allows local users to cause an unspecified denial of service via unknown vectors, possibly during a short time window on startup.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade heartbeat | Jul 30, 2024 | Jul 25, 2006 |
| Gentoo Linux | — | Upgrade sys-cluster/heartbeat. | Oct 30, 2017 | Jul 25, 2006 |
| Suse | — | Upgrade heartbeat-ldirectordUpgrade heartbeatUpgrade heartbeat-pilsUpgrade heartbeat-stonith | Dec 12, 2013 | Jul 25, 2006 |
| Ubuntu | — | Upgrade heartbeat | Nov 8, 2024 | Jul 25, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub