ibutils: insecure handling of files in the /tmp directory
Published Nov 23, 2013
6.3
MEDIUMCVSS 2.0
EPSS 0.50%
Description
OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3) ibdiagnet_ibis.log, (4) ibdiagnet.log, (5) ibdiagnet.lst, (6) ibdiagnet.mcfdbs, (7) ibdiagnet.pkey, (8) ibdiagnet.psl, (9) ibdiagnet.slvl, or (10) ibdiagnet.sm in /tmp/.
Affected products
No data.
Configuration 1
- 6.0
Configuration 2
- 1.5.7
No data.
Red Hat Enterprise Linux 6
ibutils-0:1.5.7-8.el6
Fixed · RHSA-2013:1661
Red Hat Enterprise Linux 6
infinipath-psm-0:3.0.1-115.1015_open.2.el6
Fixed · RHSA-2013:1661
Red Hat Enterprise Linux 6
libibverbs-0:1.1.7-1.el6
Fixed · RHSA-2013:1661
Red Hat Enterprise Linux 6
libmlx4-0:1.0.5-4.el6.1
Fixed · RHSA-2013:1661
Red Hat Enterprise Linux 6
librdmacm-0:1.0.17-1.el6
Fixed · RHSA-2013:1661
Red Hat Enterprise Linux 6
mpitests-0:3.2-9.el6
Fixed · RHSA-2013:1661
Red Hat Enterprise Linux 6
mstflint-0:3.0-0.6.g6961daa.1.el6
Fixed · RHSA-2013:1661
Red Hat Enterprise Linux 6
openmpi-0:1.5.4-2.el6
Fixed · RHSA-2013:1661
Red Hat Enterprise Linux 6
perftest-0:2.0-2.el6
Fixed · RHSA-2013:1661
Red Hat Enterprise Linux 6
qperf-0:0.4.9-1.el6
Fixed · RHSA-2013:1661
Red Hat Enterprise Linux 6
rdma-0:3.10-3.el6
Fixed · RHSA-2013:1661
Red Hat Enterprise Linux 5
ibutils
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | ibutils-0:1.5.7-8.el6 | Fixed | RHSA-2013:1661 |
| Red Hat Enterprise Linux 6 | infinipath-psm-0:3.0.1-115.1015_open.2.el6 | Fixed | RHSA-2013:1661 |
| Red Hat Enterprise Linux 6 | libibverbs-0:1.1.7-1.el6 | Fixed | RHSA-2013:1661 |
| Red Hat Enterprise Linux 6 | libmlx4-0:1.0.5-4.el6.1 | Fixed | RHSA-2013:1661 |
| Red Hat Enterprise Linux 6 | librdmacm-0:1.0.17-1.el6 | Fixed | RHSA-2013:1661 |
| Red Hat Enterprise Linux 6 | mpitests-0:3.2-9.el6 | Fixed | RHSA-2013:1661 |
| Red Hat Enterprise Linux 6 | mstflint-0:3.0-0.6.g6961daa.1.el6 | Fixed | RHSA-2013:1661 |
| Red Hat Enterprise Linux 6 | openmpi-0:1.5.4-2.el6 | Fixed | RHSA-2013:1661 |
| Red Hat Enterprise Linux 6 | perftest-0:2.0-2.el6 | Fixed | RHSA-2013:1661 |
| Red Hat Enterprise Linux 6 | qperf-0:0.4.9-1.el6 | Fixed | RHSA-2013:1661 |
| Red Hat Enterprise Linux 6 | rdma-0:3.10-3.el6 | Fixed | RHSA-2013:1661 |
| Red Hat Enterprise Linux 5 | ibutils | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (12)
- http://rhn.redhat.com/errata/RHSA-2013-1661.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://seclists.org/fulldisclosure/2013/Mar/87 mailing-listx_refsource_FULLDISCExploit
- http://www.openwall.com/lists/oss-security/2013/03/19/8 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2013/03/26/1 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2013/03/26/11 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2013/03/26/4 mailing-listx_refsource_MLIST
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html x_refsource_CONFIRM
- http://www.securityfocus.com/bid/58335 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2013-2561 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=927430 x_refsource_CONFIRMIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2013-2561
- https://www.cve.org/CVERecord?id=CVE-2013-2561
| Link | Providers | Tags |
|---|---|---|
| http://rhn.redhat.com/errata/RHSA-2013-1661.html | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| http://seclists.org/fulldisclosure/2013/Mar/87 | mailing-listx_refsource_FULLDISCExploit | |
| http://www.openwall.com/lists/oss-security/2013/03/19/8 | mailing-listx_refsource_MLIST | |
| http://www.openwall.com/lists/oss-security/2013/03/26/1 | mailing-listx_refsource_MLIST | |
| http://www.openwall.com/lists/oss-security/2013/03/26/11 | mailing-listx_refsource_MLIST | |
| http://www.openwall.com/lists/oss-security/2013/03/26/4 | mailing-listx_refsource_MLIST | |
| http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html | x_refsource_CONFIRM | |
| http://www.securityfocus.com/bid/58335 | vdb-entryx_refsource_BID | |
| https://access.redhat.com/security/cve/CVE-2013-2561 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=927430 | x_refsource_CONFIRMIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-2561 | ||
| https://www.cve.org/CVERecord?id=CVE-2013-2561 |
Change history (0)
No recorded changes yet.