DSA-5366-1 multipath-tools -- multipath-toolsID: oval:org.secpod.oval:def:89368 | Date: (C)2023-11-27 (M)2023-11-30 |
Class: PATCH | Family: unix |
The Qualys Research Labs reported an authorization bypass and a symlink attack in multipath-tools, a set of tools to drive the Device Mapper multipathing driver, which may result in local privilege escalation. Please refer to /usr/share/doc/multipath-tools/NEWS.Debian.gz for backwards-incompatible changes in this update.
Product: |
multipath-udeb |
kpartx |
multipath-tools |