Oval Definition:oval:com.redhat.rhsa:def:20120311
Revision Date:2012-02-21Version:634
Title:RHSA-2012:0311: ibutils security and bug fix update (Low)
Description:The ibutils packages provide InfiniBand network and path diagnostics.

  • It was found that the ibmssh executable had an insecure relative RPATH (runtime library search path) set in the ELF (Executable and Linking Format) header. A local user able to convince another user to run ibmssh in an attacker-controlled directory could run arbitrary code with the privileges of the victim. (CVE-2008-3277)

    This update also fixes the following bug:

  • Under certain circumstances, the "ibdiagnet -r" command could suffer from memory corruption and terminate with a "double free or corruption" message and a backtrace. With this update, the correct memory management function is used to prevent the corruption. (BZ#711779)

    All users of ibutils are advised to upgrade to these updated packages, which contain backported patches to correct these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2008-3277
    RHSA-2012:0311
    RHSA-2012:0311-03
    RHSA-2012:0311-03
    Platform(s):Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • ibutils is earlier than 0:1.2-11.2.el5
  • AND ibutils is signed with Red Hat redhatrelease2 key
  • ibutils-devel is earlier than 0:1.2-11.2.el5
  • AND ibutils-devel is signed with Red Hat redhatrelease2 key
  • ibutils-libs is earlier than 0:1.2-11.2.el5
  • AND ibutils-libs is signed with Red Hat redhatrelease2 key
  • BACK