[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-2561Date: (C)2013-11-28   (M)2023-12-22


OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3) ibdiagnet_ibis.log, (4) ibdiagnet.log, (5) ibdiagnet.lst, (6) ibdiagnet.mcfdbs, (7) ibdiagnet.pkey, (8) ibdiagnet.psl, (9) ibdiagnet.slvl, or (10) ibdiagnet.sm in /tmp/.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.3
Exploit Score: 3.4
Impact Score: 9.2
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
http://seclists.org/fulldisclosure/2013/Mar/87
BID-58335
RHSA-2013:1661
http://www.openwall.com/lists/oss-security/2013/03/26/1
http://www.openwall.com/lists/oss-security/2013/03/26/11
http://www.openwall.com/lists/oss-security/2013/03/19/8
http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
https://bugzilla.redhat.com/show_bug.cgi?id=927430

CPE    1
cpe:/a:openfabrics:ibutils:1.5.7
CWE    1
CWE-59
OVAL    14
oval:org.secpod.oval:def:1500307
oval:org.secpod.oval:def:205780
oval:org.secpod.oval:def:205782
oval:org.secpod.oval:def:1600312
...

© SecPod Technologies