CVE-2012-4516 Information

Description

librdmacm 1.0.16 when ibacm.port is not specified connects to port 6125 which allows remote attackers to specify the address resolution information for the application via a malicious ib_acm service.

Reference

http://git.openfabrics.org/git?p=~shefty/librdmacm.git;a=commitdiff;h=4b5c1aa734e0e734fc2ba3cd41d0ddf02170af6d http://www.openwall.com/lists/oss-security/2012/10/11/6 http://www.openwall.com/lists/oss-security/2012/10/11/9 http://www.securityfocus.com/bid/55896 https://bugzilla.redhat.com/show_bug.cgi?id=865483

Share on: