PT-2012-5454 · Openfabrics Alliance+2 · Librdmacm+2

Florian Weimer

+1

·

Published

2012-10-22

·

Updated

2023-02-13

·

CVE-2012-4516

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions librdmacm version 1.0.16
Description The issue allows remote attackers to specify address resolution information for the application via a malicious ib acm service when ibacm.port is not specified, causing librdmacm to connect to port 6125.
Recommendations For librdmacm version 1.0.16, consider specifying the ibacm.port to avoid connecting to the default port 6125, which can be exploited by a malicious ib acm service. As a temporary workaround, restrict access to the ib acm service to minimize the risk of exploitation.

Exploit

Fix

Related Identifiers

CESA-2013_1661
CVE-2012-4516
RHSA-2013:1661
RHSA-2013_1661

Affected Products

Centos
Red Hat
Librdmacm