The (1) SAPDatabase and (2) SAPInstance scripts in OCF Resource Agents (aka resource-agents or cluster-agents) 1.0.3 in Linux-HA place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade rgmanager | Dec 1, 2016 | Oct 20, 2010 |
| Gentoo Linux | — | Upgrade games-sports/racer-bin.Upgrade app-misc/ca-certificates.Upgrade net-libs/webkit-gtk.Upgrade net-misc/mrouted.Upgrade dev-util/qt-creator.Upgrade gnome-base/gdm.Upgrade dev-util/oprofile.Upgrade sys-apps/shadow.Upgrade dev-php/PEAR-Mail.Upgrade app-admin/syslog-ng.Upgrade sys-cluster/resource-agents.Upgrade net-libs/libsoup.Upgrade dev-libs/xmlsec.Upgrade media-libs/fmod.Upgrade dev-vcs/gitolite.Upgrade net-misc/rsync.Upgrade sys-cluster/rgmanager.Upgrade net-analyzer/sflowtool.Upgrade dev-db/unixODBC.Upgrade app-office/gnucash.Upgrade dev-php/PEAR-PEAR.Upgrade media-sound/lastfmplayer.Upgrade media-libs/xine-lib.Upgrade sys-fs/lvm2.Upgrade net-misc/vino.Upgrade x11-apps/xrdb. | Oct 30, 2017 | Oct 20, 2010 |
| Oracle_linux | — | Upgrade rgmanager | Oct 16, 2024 | Oct 20, 2010 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 30, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub