Description
An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manager daemon to execute a script as root and thereby gain root access on the machine.
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 2.0 | Impact: 6.0Attack Vector: Local
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Changed
Confidentiality: High
Integrity: High
Availability: High
Affected Packages5 packages
▶Ubuntupacemaker< 1.1.10+git20130802-1ubuntu2.4+1 Also affects: Enterprise Linux 7.3, 7.4, 7.5, 7.6
🔴Vulnerability Details
4GHSAGHSA-5wmv-gcg2-v47h: An authorization flaw was found in Pacemaker before 1↗2022-05-13 ▶ OSVCVE-2016-7035: An authorization flaw was found in Pacemaker before 1↗2018-09-10 ▶ CVEListCVE-2016-7035: An authorization flaw was found in Pacemaker before 1↗2018-09-10 ▶ OSVpacemaker vulnerabilities↗2017-10-24 ▶ 📋Vendor Advisories
3UbuntuPacemaker vulnerabilities↗2017-10-24 ▶ Red Hatpacemaker: Privilege escalation due to improper guarding of IPC communication↗2016-11-03 ▶ DebianCVE-2016-7035: pacemaker - An authorization flaw was found in Pacemaker before 1.1.16, where it did not pro...↗2016 ▶ 💬Community
2BugzillaCVE-2016-7035 pacemaker: Privilege escalation due to improper guarding of IPC communication [fedora-all]↗2016-11-03 ▶ BugzillaCVE-2016-7035 pacemaker: Privilege escalation due to improper guarding of IPC communication↗2016-08-24 ▶