Vulnerability Description
ibacm before 1.0.6 does not properly manage reference counts for multicast connections, which allows remote attackers to cause a denial of service (ibacm service crash) via a crafted join response.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openfabrics | Ibacm | <= 1.0.5 |
Related Weaknesses (CWE)
References
- http://comments.gmane.org/gmane.linux.drivers.rdma/11659Patch
- http://git.openfabrics.org/git?p=~shefty/ibacm.git%3Ba=commit%3Bh=c7d28b35d64333
- http://rhn.redhat.com/errata/RHSA-2013-0509.html
- http://www.openwall.com/lists/oss-security/2012/10/11/6
- http://www.openwall.com/lists/oss-security/2012/10/11/9
- http://www.securityfocus.com/bid/55890
- https://bugzilla.redhat.com/show_bug.cgi?id=865492
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79396
- http://comments.gmane.org/gmane.linux.drivers.rdma/11659Patch
- http://git.openfabrics.org/git?p=~shefty/ibacm.git%3Ba=commit%3Bh=c7d28b35d64333
- http://rhn.redhat.com/errata/RHSA-2013-0509.html
- http://www.openwall.com/lists/oss-security/2012/10/11/6
- http://www.openwall.com/lists/oss-security/2012/10/11/9
- http://www.securityfocus.com/bid/55890
- https://bugzilla.redhat.com/show_bug.cgi?id=865492
FAQ
What is CVE-2012-4517?
CVE-2012-4517 is a vulnerability with a CVSS score of 5.0 (MEDIUM). ibacm before 1.0.6 does not properly manage reference counts for multicast connections, which allows remote attackers to cause a denial of service (ibacm service crash) via a crafted join response.
How severe is CVE-2012-4517?
CVE-2012-4517 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-4517?
Check the references section above for vendor advisories and patch information. Affected products include: Openfabrics Ibacm.