fence_manual, as used in fence 2.02.00-r1 and possibly cman, allows local users to modify arbitrary files via a symlink attack on the fence_manual.fifo temporary file.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade sys-cluster/fence. | Oct 30, 2017 | Oct 15, 2008 |
| Ubuntu | — | Upgrade cmanUpgrade gfs2-toolsUpgrade fenceUpgrade ccsUpgrade rgmanagerUpgrade libcman1 | Nov 8, 2024 | Oct 15, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub