CVE-2013-2561
published 2013-11-23CVE-2013-2561: OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3) ibdiagnet_ibis.log…
PriorityP420medium6.3CVSS 2.0
AVLACMAuNCNICAC
EPSS
0.47%
38.0th percentile
OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3) ibdiagnet_ibis.log, (4) ibdiagnet.log, (5) ibdiagnet.lst, (6) ibdiagnet.mcfdbs, (7) ibdiagnet.pkey, (8) ibdiagnet.psl, (9) ibdiagnet.slvl, or (10) ibdiagnet.sm in /tmp/.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ibutils | < ibutils 1.5.7-2 (bookworm) | ibutils 1.5.7-2 (bookworm) |
| openfabrics | ibutils | — | — |
| openfabrics | ibutils | >= 0 < 1.5.7-2 | 1.5.7-2 |
| openfabrics | ibutils | >= 0 < 1.5.7-2 | 1.5.7-2 |
| openfabrics | ibutils | >= 0 < 1.5.7-2 | 1.5.7-2 |
| openfabrics | ibutils | >= 0 < 1.5.7-2 | 1.5.7-2 |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv2.06.3MEDIUMAV:L/AC:M/Au:N/C:N/I:C/A:C
osv6.3MEDIUM
vendor_debian6.3LOW
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ibutils: insecure handling of files in the /tmp directory
vendor_redhat·2013-03-06·CVSS 6.3
CVE-2013-2561 [MEDIUM] ibutils: insecure handling of files in the /tmp directory
ibutils: insecure handling of files in the /tmp directory
OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3) ibdiagnet_ibis.log, (4) ibdiagnet.log, (5) ibdiagnet.lst, (6) ibdiagnet.mcfdbs, (7) ibdiagnet.pkey, (8) ibdiagnet.psl, (9) ibdiagnet.slvl, or (10) ibdiagnet.sm in /tmp/.
Package: ibutils (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2013-2561: ibutils - OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a ...
vendor_debian·2013·CVSS 6.3
CVE-2013-2561 [MEDIUM] CVE-2013-2561: ibutils - OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a ...
OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3) ibdiagnet_ibis.log, (4) ibdiagnet.log, (5) ibdiagnet.lst, (6) ibdiagnet.mcfdbs, (7) ibdiagnet.pkey, (8) ibdiagnet.psl, (9) ibdiagnet.slvl, or (10) ibdiagnet.sm in /tmp/.
Scope: local
bookworm: resolved (fixed in 1.5.7-2)
bullseye: resolved (fixed in 1.5.7-2)
forky: resolved (fixed in 1.5.7-2)
sid: resolved (fixed in 1.5.7-2)
trixie: resolved (fixed in 1.5.7-2)
GHSA
GHSA-4q9r-mj23-g4vq: OpenFabrics ibutils 1
ghsa_unreviewed·2022-05-14
CVE-2013-2561 [MEDIUM] CWE-59 GHSA-4q9r-mj23-g4vq: OpenFabrics ibutils 1
OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3) ibdiagnet_ibis.log, (4) ibdiagnet.log, (5) ibdiagnet.lst, (6) ibdiagnet.mcfdbs, (7) ibdiagnet.pkey, (8) ibdiagnet.psl, (9) ibdiagnet.slvl, or (10) ibdiagnet.sm in /tmp/.
OSV
CVE-2013-2561: OpenFabrics ibutils 1
osv·2013-11-23·CVSS 6.3
CVE-2013-2561 [MEDIUM] CVE-2013-2561: OpenFabrics ibutils 1
OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3) ibdiagnet_ibis.log, (4) ibdiagnet.log, (5) ibdiagnet.lst, (6) ibdiagnet.mcfdbs, (7) ibdiagnet.pkey, (8) ibdiagnet.psl, (9) ibdiagnet.slvl, or (10) ibdiagnet.sm in /tmp/.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2013-1661.htmlhttp://seclists.org/fulldisclosure/2013/Mar/87http://www.openwall.com/lists/oss-security/2013/03/19/8http://www.openwall.com/lists/oss-security/2013/03/26/1http://www.openwall.com/lists/oss-security/2013/03/26/11http://www.openwall.com/lists/oss-security/2013/03/26/4http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.securityfocus.com/bid/58335https://bugzilla.redhat.com/show_bug.cgi?id=927430http://rhn.redhat.com/errata/RHSA-2013-1661.htmlhttp://seclists.org/fulldisclosure/2013/Mar/87http://www.openwall.com/lists/oss-security/2013/03/19/8http://www.openwall.com/lists/oss-security/2013/03/26/1http://www.openwall.com/lists/oss-security/2013/03/26/11http://www.openwall.com/lists/oss-security/2013/03/26/4http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.securityfocus.com/bid/58335https://bugzilla.redhat.com/show_bug.cgi?id=927430
2013-11-23
Published