heartbeat.c in heartbeat before 2.0.6 sets insecure permissions in a shmget call for shared memory, which allows local users to cause an unspecified denial of service via unknown vectors, possibly during a short time window on startup.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Heartbeat | Linux-ha | * | 2.0.5 (including) |
Heartbeat | Ubuntu | dapper | * |
Heartbeat | Ubuntu | devel | * |
Heartbeat | Ubuntu | edgy | * |
Heartbeat | Ubuntu | feisty | * |
Heartbeat | Ubuntu | gutsy | * |