Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2013-1661

Опубликовано: 25 нояб. 2013
Источник: oracle-oval
Платформа: Oracle Linux 6

Описание

ELSA-2013-1661: rdma stack security, bug fix, and enhancement update (MODERATE)

ibutils [1.5.7-8]

  • Add the -output patch to have programs use /var/cache/ibutils instead of /tmp Resolves: bz958569

infinipath-psm

  • Put the udev rules file in the right place Resolves: rhbz866732
  • include a patch from upstream to fix undefined references Resolves: rhbz887730

[3.0.1-115.1015_open.1]

  • New upstream releas Resolves: rhbz818789

[ 2.9-926.1005_open.2]

  • Add the udev rules file to close Resolves: rhbz747406

[2.9-926.1005_open.1]

  • New upstream version. Resolves: rhbz635915
  • Include the -execstack patch to get libinfinipath.so correctly labeled as not executing the stack. Resolves: rhbz612936

[1.13-2]

  • Use macros for lib and include directories, and include dist tag in release field.
  • Corrected License field.
  • Corrected Requires lines for libuuid.
  • Add Exclusive-arch x86_64 Related: rhbz570274

[1.13-1]

  • Initial build.

libibverbs [1.1.7-1]

  • Update to latest upstream release
  • Remove patches that are now part of upstream
  • Fix ibv_srq_pingpong with negative value to -s option
  • Resolves: bz879191

libmlx4 [1.0.5-4.el6.1]

  • Fix dracut module for compatibility with RHEL6 version of dracut.
  • Resolves: bz789121

[1.0.5-4]

  • Add dracut module
  • Fix URL

[1.0.5-3]

  • Reduce the dependencies of the setup script even further, it no longer needs grep

[1.0.5-2]

  • The setup script needs to have execute permissions

[1.0.5-1]

  • Update to latest upstream
  • Drop awk based setup for a bash based setup, making including the setup code on an initramfs easier
  • Modernize spec file
  • Related: bz950915

librdmacm [1.0.17-1]

  • Official 1.0.17 release
  • The fix to bug 866221 got kicked back as incomplete last time, fix it for real this time.
  • Intel adapters that use the qib driver don't like using inline data, so use a memory region that is registered instead
  • Resolves: bz866221, bz828071

mpitests [3.2-9]

  • Backport fixes from RHEL-7 Resolves: rhbz1002332

[3.2-7]

  • include BuildRequires: hwloc-devel from RHEL-7.0
  • Add win_free patch to close Resolves: rhbz734023

mstflint [3.0-0.6.g6961daa.1]

  • Update to newer tarball that resolves licensing issues with the last tarball
  • Related: bz818183

[3.0-0.5.gff93670.1]

  • Update to latest upstream version, which includes ConnectIB support
  • Resolves: bz818183

openmpi [1.5.4-2.0.1]

  • Obsolete openmpi-psm-devel for 32bit

[1.5.4-2]

  • Fix the build process by getting rid of the -build patch and autogen to fix Resolves: rhbz749115

perftest [2.0-2]

  • Fix rpmdiff detected error. Upstream overrode our cflags so stack protector got turned off.
  • Related: bz806183

[2.0-1]

  • Update to latest upstream release
  • We had to drop ib_clock_test program as no equivalent exists in the latest release
  • Resolves: bz806183, bz806185, bz830099

[1.3.0-2]

  • Update to latest upstream release
  • No longer strip rocee related code out, we can compile with it now
  • Related: bz739138

qperf [0.4.9-1.0.1]

  • Rebuild for ULN upgrade

[0.4.9-1]

  • Update to latest upstream release
  • Resolves: bz814909, bz840269

rdma [3.10-3.0.1]

  • Append mlx4_* module parameters when insmod the modules [orabug 17429249] (Joe Jin)
  • Delay load mlx4_* to prevent hung when start udev. [orabug 16897608] (Joe Jin)
  • Fix FMR load, persistent ib0 subinterfaces, remove kudzu dependency (Chien Yen)
  • Add SDP to rdma.conf and rdma.init (Chien Yen)
  • Support Mellanox OFED 1.5.5 (Chien Yen)

[3.10-3]

  • Replace an errant usage of PARENTDEVICE with PHYSDEV in ifdown-ib
  • Related: bz990288

[3.10-2]

  • Somehow during editing I accidentally deleted a single character from the post scriptlet. rpmdiff caught it, now I'm fixing it.
  • Resolves: bz990288

[3.10-1]

  • Bump version to match final kernel submission
  • Add support for P_Key interfaces to ifup-ib and ifdown-ib

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

ibutils

1.5.7-8.el6

ibutils-devel

1.5.7-8.el6

ibutils-libs

1.5.7-8.el6

infinipath-psm

3.0.1-115.1015_open.2.el6

infinipath-psm-devel

3.0.1-115.1015_open.2.el6

libibverbs

1.1.7-1.el6

libibverbs-devel

1.1.7-1.el6

libibverbs-devel-static

1.1.7-1.el6

libibverbs-utils

1.1.7-1.el6

libmlx4

1.0.5-4.el6.1

libmlx4-static

1.0.5-4.el6.1

librdmacm

1.0.17-1.el6

librdmacm-devel

1.0.17-1.el6

librdmacm-static

1.0.17-1.el6

librdmacm-utils

1.0.17-1.el6

mpitests-mvapich

3.2-9.el6

mpitests-mvapich-psm

3.2-9.el6

mpitests-mvapich2

3.2-9.el6

mpitests-mvapich2-psm

3.2-9.el6

mpitests-openmpi

3.2-9.el6

mstflint

3.0-0.6.g6961daa.1.el6

openmpi

1.5.4-2.0.1.el6

openmpi-devel

1.5.4-2.0.1.el6

perftest

2.0-2.el6

qperf

0.4.9-1.0.1.el6

rdma

3.10-3.0.1.el6

Oracle Linux i686

ibutils

1.5.7-8.el6

ibutils-devel

1.5.7-8.el6

ibutils-libs

1.5.7-8.el6

libibverbs

1.1.7-1.el6

libibverbs-devel

1.1.7-1.el6

libibverbs-devel-static

1.1.7-1.el6

libibverbs-utils

1.1.7-1.el6

libmlx4

1.0.5-4.el6.1

libmlx4-static

1.0.5-4.el6.1

librdmacm

1.0.17-1.el6

librdmacm-devel

1.0.17-1.el6

librdmacm-static

1.0.17-1.el6

librdmacm-utils

1.0.17-1.el6

mpitests-mvapich

3.2-9.el6

mpitests-mvapich2

3.2-9.el6

mpitests-openmpi

3.2-9.el6

mstflint

3.0-0.6.g6961daa.1.el6

openmpi

1.5.4-2.0.1.el6

openmpi-devel

1.5.4-2.0.1.el6

perftest

2.0-2.el6

qperf

0.4.9-1.0.1.el6

rdma

3.10-3.0.1.el6

Связанные CVE

Связанные уязвимости

ubuntu
почти 12 лет назад

OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3) ibdiagnet_ibis.log, (4) ibdiagnet.log, (5) ibdiagnet.lst, (6) ibdiagnet.mcfdbs, (7) ibdiagnet.pkey, (8) ibdiagnet.psl, (9) ibdiagnet.slvl, or (10) ibdiagnet.sm in /tmp/.

redhat
больше 12 лет назад

OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3) ibdiagnet_ibis.log, (4) ibdiagnet.log, (5) ibdiagnet.lst, (6) ibdiagnet.mcfdbs, (7) ibdiagnet.pkey, (8) ibdiagnet.psl, (9) ibdiagnet.slvl, or (10) ibdiagnet.sm in /tmp/.

nvd
почти 12 лет назад

OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3) ibdiagnet_ibis.log, (4) ibdiagnet.log, (5) ibdiagnet.lst, (6) ibdiagnet.mcfdbs, (7) ibdiagnet.pkey, (8) ibdiagnet.psl, (9) ibdiagnet.slvl, or (10) ibdiagnet.sm in /tmp/.

debian
почти 12 лет назад

OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary fi ...

ubuntu
почти 13 лет назад

librdmacm 1.0.16, when ibacm.port is not specified, connects to port 6125, which allows remote attackers to specify the address resolution information for the application via a malicious ib_acm service.