PT-2014-2065 · Red Hat · Ibutils+1

Published

2012-02-21

·

Updated

2019-04-22

·

CVE-2008-3277

CVSS v2.0

4.4

Medium

VectorAV:L/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ibutils versions prior to 1.5.7-2.el6 ibutils versions prior to 1.2-11.2.el5
Description The issue is related to an untrusted search path vulnerability in a Red Hat build script for the ibmssh executable. This vulnerability allows local users to gain privileges via a Trojan Horse program in refix/lib/, due to an incorrect RPATH setting in the ELF header.
Recommendations For ibutils versions prior to 1.5.7-2.el6, update to version 1.5.7-2.el6 or later. For ibutils versions prior to 1.2-11.2.el5, update to version 1.2-11.2.el5 or later.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-3277
RHSA-2012:0311
RHSA-2012_0311

Affected Products

Red Hat
Ibutils