PT-2013-3843 · Openfabrics+2 · Ibutils+2

Vincent Danen

·

Published

2013-11-20

·

Updated

2019-04-22

·

CVE-2013-2561

CVSS v2.0

6.3

Medium

VectorAV:L/AC:M/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenFabrics ibutils version 1.5.7
Description The issue allows local users to overwrite arbitrary files via a symlink attack on several files in /tmp/, including ibdiagnet.db, ibdiagnet.fdbs, ibdiagnet ibis.log, ibdiagnet.log, ibdiagnet.lst, ibdiagnet.mcfdbs, ibdiagnet.pkey, ibdiagnet.psl, ibdiagnet.slvl, and ibdiagnet.sm.
Recommendations For OpenFabrics ibutils version 1.5.7, consider restricting access to the files in /tmp/ that are vulnerable to the symlink attack until a patch is available. As a temporary workaround, avoid using the vulnerable files in /tmp/ to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2013_1661
CVE-2013-2561
RHSA-2013:1661
RHSA-2013_1661

Affected Products

Centos
Red Hat
Ibutils