LWN.net Logo

ibutils: code execution

Package(s):ibutils CVE #(s):CVE-2008-3277
Created:February 21, 2012 Updated:March 8, 2012
Description: From the Red Hat advisory:

It was found that the ibmssh executable had an insecure relative RPATH (runtime library search path) set in the ELF (Executable and Linking Format) header. A local user able to convince another user to run ibmssh in an attacker-controlled directory could run arbitrary code with the privileges of the victim.

Alerts:
Red Hat RHSA-2012:0311-03 2012-02-21
Oracle ELSA-2012-0311 2012-03-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds