|
|
Log in / Subscribe / Register

rdma: multiple vulnerabilities

Package(s):RDMA CVE #(s):CVE-2012-4517 CVE-2012-4518
Created:February 21, 2013 Updated:March 11, 2013
Description: From the Red Hat advisory:

A denial of service flaw was found in the way ibacm managed reference counts for multicast connections. An attacker could send specially-crafted multicast packets that would cause the ibacm daemon to crash. (CVE-2012-4517)

It was found that the ibacm daemon created some files with world-writable permissions. A local attacker could use this flaw to overwrite the contents of the ibacm.log or ibacm.port file, allowing them to mask certain actions from the log or cause ibacm to run on a non-default port. (CVE-2012-4518)

Alerts:
CentOS CESA-2013:0509 RDMA 2013-03-09
CentOS CESA-2013:0509 opensm 2013-03-09
CentOS CESA-2013:0509 librdmacm 2013-03-09
CentOS CESA-2013:0509 libmlx4 2013-03-09
CentOS CESA-2013:0509 libibverbs 2013-03-09
CentOS CESA-2013:0509 libibumad 2013-03-09
CentOS CESA-2013:0509 libibmad 2013-03-09
CentOS CESA-2013:0509 infiniband-diags 2013-03-09
CentOS CESA-2013:0509 ibutils 2013-03-09
CentOS CESA-2013:0509 ibsim 2013-03-09
CentOS CESA-2013:0509 ibacm 2013-03-09
Scientific Linux SL-rdma-20130304 rdma 2013-03-04
Oracle ELSA-2013-0509 RDMA 2013-02-25
Red Hat RHSA-2013:0509-02 RDMA 2013-02-21

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds