CVE-2012-4517: Medium severity OpenFabrics ibacm vulnerability
A denial of service flaw was found in the way ibacm, an InfiniBand communication manager assistant, performed management of reference counts for multicast connections. The default reference count value for multicast connection is set to zero and when the multicast connection got released, an attempt was made to free it, possibly resulting in ibacm service / daemon crash.
Upstream patch: [1] http://git.openfabrics.org/git?p=~shefty/ibacm.git;a=commit;h=c7d28b35d64333c262de3ec972c426423dadccf9
Other sources
ibacm before 1.0.6 does not properly manage reference counts for multicast connections, which allows remote attackers to cause a denial of service (ibacm service crash) via a crafted join response.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4517?
CVE-2012-4517 is categorized as a denial of service vulnerability.
How do I fix CVE-2012-4517?
To fix CVE-2012-4517, upgrade to a version of ibacm that exceeds 1.0.5.
What software is affected by CVE-2012-4517?
CVE-2012-4517 affects ibacm versions 1.0.5 and earlier.
What type of attack does CVE-2012-4517 enable?
CVE-2012-4517 enables denial of service attacks by improperly managing reference counts.
Is CVE-2012-4517 easy to exploit?
Yes, CVE-2012-4517 can be exploited relatively easily due to its nature of managing multicast connections.