OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3) ibdiagnet_ibis.log, (4) ibdiagnet.log, (5) ibdiagnet.lst, (6) ibdiagnet.mcfdbs, (7) ibdiagnet.pkey, (8) ibdiagnet.psl, (9) ibdiagnet.slvl, or (10) ibdiagnet.sm in /tmp/.
References
Configurations
History
No history.
Information
Published : 2013-11-23 18:55
Updated : 2019-04-22 17:48
NVD link : CVE-2013-2561
Mitre link : CVE-2013-2561
CVE.ORG link : CVE-2013-2561
JSON object : View
Products Affected
redhat
- enterprise_linux
openfabrics
- ibutils
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')