First published: Fri Oct 29 2010(Updated: )
The default configuration of libsdp.conf in libsdp 1.1.104 and earlier creates log files in /tmp, which allows local users to overwrite arbitrary files via a (1) symlink or (2) hard link attack on the libsdp.log.##### temporary file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Openfabrics Libsdp | =1.1.102 | |
Openfabrics Libsdp | <=1.1.104 | |
Openfabrics Libsdp | =1.1.103 | |
Openfabrics Libsdp | =1.1.99 | |
Openfabrics Libsdp | =1.1.101 | |
Openfabrics Libsdp | =1.1.100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.