PT-2012-5454 · Openfabrics Alliance+2 · Librdmacm+2
Florian Weimer
+1
·
Published
2012-10-22
·
Updated
2023-02-13
·
CVE-2012-4516
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
librdmacm version 1.0.16
Description
The issue allows remote attackers to specify address resolution information for the application via a malicious ib acm service when ibacm.port is not specified, causing librdmacm to connect to port 6125.
Recommendations
For librdmacm version 1.0.16, consider specifying the
ibacm.port to avoid connecting to the default port 6125, which can be exploited by a malicious ib acm service. As a temporary workaround, restrict access to the ib acm service to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Centos
Red Hat
Librdmacm