vendor:
Heartbeat
by:
Nash Leon
7.2
CVSS
HIGH
Insecure Shared Memory
264
CWE
Product Name: Heartbeat
Affected Version From: 2.0.5
Affected Version To: 2.0.6
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2006
Heartbeat < 2.0.6 Insecure Shared Memory - Local Denial of Service
Since Linux-HA Heartbeat has insecure default permissions set on shared memory, local attackers may be able to cause a denial of service. Exploitation would most likely result in a system crash, loss of data, and resource exhaustion, leading to a denial of service if critical files are accessed improperly or overwritten in the attack.
Mitigation:
Ensure that shared memory permissions are set to secure values.