PT-2013-3843 · Openfabrics+2 · Ibutils+2

Vincent Danen

·

Publicado

2013-11-20

·

Atualizado

2019-04-22

·

CVE-2013-2561

CVSS v2.0

6.3

Média

VetorAV:L/AC:M/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenFabrics ibutils version 1.5.7
Description The issue allows local users to overwrite arbitrary files via a symlink attack on several files in /tmp/, including ibdiagnet.db, ibdiagnet.fdbs, ibdiagnet ibis.log, ibdiagnet.log, ibdiagnet.lst, ibdiagnet.mcfdbs, ibdiagnet.pkey, ibdiagnet.psl, ibdiagnet.slvl, and ibdiagnet.sm.
Recommendations For OpenFabrics ibutils version 1.5.7, consider restricting access to the files in /tmp/ that are vulnerable to the symlink attack until a patch is available. As a temporary workaround, avoid using the vulnerable files in /tmp/ to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2013_1661
CVE-2013-2561
RHSA-2013:1661
RHSA-2013_1661

Produtos afetados

Centos
Red Hat
Ibutils