CVE-2011-3345: Buffer Overflow
ulp/sdp/sdpproc.c in the ibsdp module (aka ibsdp.ko) in the ofakernel package in the InfiniBand driver implementation in OpenFabrics Enterprise Distribution (OFED) before 1.5.3 does not properly handle certain non-array variables, which allows local users to cause a denial of service (stack memory corruption and system crash) by reading the /proc/net/sdpstats file.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3345?
CVE-2011-3345 has a moderate severity rating as it allows local users to cause a denial of service.
How do I fix CVE-2011-3345?
To fix CVE-2011-3345, you should upgrade to OpenFabrics Enterprise Distribution version 1.5.3 or later.
Which versions of OpenFabrics Enterprise Distribution are affected by CVE-2011-3345?
CVE-2011-3345 affects OpenFabrics Enterprise Distribution versions up to and including 1.5.2.
How does CVE-2011-3345 impact system stability?
CVE-2011-3345 can lead to instability by causing a stack memory exhaustion which results in a denial of service.
Who is affected by CVE-2011-3345?
CVE-2011-3345 primarily affects local users of the affected OpenFabrics Enterprise Distribution installations.