Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.123718
Category:Oracle Linux Local Security Checks
Title:Oracle: Security Advisory (ELSA-2013-0509)
Summary:The remote host is missing an update for the 'ibacm, ibsim, ibutils, infiniband-diags, infinipath-psm, libibmad, libibumad, libibverbs, libmlx4, librdmacm, opensm, rdma' package(s) announced via the ELSA-2013-0509 advisory.
Description:Summary:
The remote host is missing an update for the 'ibacm, ibsim, ibutils, infiniband-diags, infinipath-psm, libibmad, libibumad, libibverbs, libmlx4, librdmacm, opensm, rdma' package(s) announced via the ELSA-2013-0509 advisory.

Vulnerability Insight:
ibacm
[1.0.8-0.git7a3adb7]
- Update to latest upstream via git repo
- Resolves: bz866222, bz866223

ibsim
[0.5-7]
- Bump and rebuild against latest opensm
- Related: bz756396

ibutils
[1.5.7-7]
- Bump and rebuild against latest opensm
- Related: bz756396

infiniband-diags
[1.5.12-5]
- Bump and rebuild against latest opensm
- Pick up fixes done for rhel5.9
- Related: bz756396

[1.5.12-4]
- Update the all_hcas patch to resolve several problems
- Give a simple help message to the ibnodes script
- Resolves: bz818606, bz847129

infinipath-psm
[3.0.1-115.1015_open.1]
- New upstream release
Resolves: rhbz818789

libibmad
[1.3.9-1]
- Update to latest upstream version (more SRIOV support)
- Related: bz756396

[1.3.8-1]
- Update to latest upstream version (for FDR link speed support)
- Related: bz750609

[1.3.7-1]
- Update to latest upstream version (1.3.4 -> 1.3.7)
- Related: bz725016

[1.3.4-1]
- New upstream version

[1.3.3-2]
- ExcludeArch s390(x) as there's no hardware support there

[1.3.3-1]
- Update to latest upstream releasee

[1.3.2-2]
- Rebuilt for [link moved to references]

[1.3.2-1]
- Update to latest upstream version
- Require the same version of libibumad as our version

[1.3.1-1]
- Update to latest upstream version

[1.2.0-3]
- Rebuilt against libtool 2.2

[1.2.0-2]
- Rebuilt for [link moved to references]

[1.2.0-1]
- Initial package for Fedora review process

libibumad
[1.3.8-1]
- Update to latest upstream releasee (more SRIOV support)
- Related: bz756396

[1.3.7-1]
- Update to latest upstream version (1.3.4 -> 1.3.7)
- Related: bz725016

[1.3.4-1]
- New upstream releasee

[1.3.3-2]
- ExcludeArch s390(x) as there is no hardware support there

[1.3.3-1]
- Update to latest upstream version

[1.3.2-3]
- Rebuilt for [link moved to references]

[1.3.2-2]
- Forgot to remove both instances of the libibcommon requires
- Add build requires on glibc-static

[1.3.2-1]
- Update to latest upstream version
- Remove requirement on libibcommon since that library is no longer needed
- Fix a problem with man page listing

[1.3.1-1]
- Update to latest upstream version

[1.2.0-3]
- Rebuilt against libtool 2.2

[1.2.0-2]
- Rebuilt for [link moved to references]

[1.2.0-1]
- Initial package for Fedora review process

libibverbs
[1.1.6-5]
- Don't print link state on iWARP links as it's always invalid
- Don't try to do ud transfers in excess of port MTU
- Resolves: bz822781

libmlx4
[1.0.4-1]
- Update to latest upstream version
- Related: bz756396

librdmacm
[1.0.17-0.git4b5c1aa]
- Pre-releasee version of 1.0.17
- Resolves a CVE vulnerability between librdmacm and ibacm
- Fixes various minor bugs in sample programs
- Resolves: bz866221, bz816074

opensm
[3.3.15-1]
- Update to latest upstream source (adds more SRIOV support)
- Fix init script when no config files are present
- ... [Please see the references for more information on the vulnerabilities]

Affected Software/OS:
'ibacm, ibsim, ibutils, infiniband-diags, infinipath-psm, libibmad, libibumad, libibverbs, libmlx4, librdmacm, opensm, rdma' package(s) on Oracle Linux 6.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-4517
55890
http://www.securityfocus.com/bid/55890
RHSA-2013:0509
http://rhn.redhat.com/errata/RHSA-2013-0509.html
[linux-rdma] 20120413 [ANNOUNCE] ibacm release 1.0.6
http://comments.gmane.org/gmane.linux.drivers.rdma/11659
[oss-security] 20121011 CVE Request -- librdmacm (one issue) / ibacm (two issues)
http://www.openwall.com/lists/oss-security/2012/10/11/6
[oss-security] 20121011 Re: CVE Request -- librdmacm (one issue) / ibacm (two issues)
http://www.openwall.com/lists/oss-security/2012/10/11/9
http://git.openfabrics.org/git?p=~shefty/ibacm.git%3Ba=commit%3Bh=c7d28b35d64333c262de3ec972c426423dadccf9
https://bugzilla.redhat.com/show_bug.cgi?id=865492
ibacm-connections-dos(79396)
https://exchange.xforce.ibmcloud.com/vulnerabilities/79396
Common Vulnerability Exposure (CVE) ID: CVE-2012-4518
http://git.openfabrics.org/git?p=~shefty/ibacm.git%3Ba=commit%3Bh=d204fca2b6298d7799e918141ea8e11e7ad43cec
CopyrightCopyright (C) 2015 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.