CVE-2010-4173
Severity CVSS v4.0:
Pending analysis
Type:
CWE-59
Link Following
Publication date:
22/11/2010
Last modified:
11/04/2025
Description
The default configuration of libsdp.conf in libsdp 1.1.104 and earlier creates log files in /tmp, which allows local users to overwrite arbitrary files via a (1) symlink or (2) hard link attack on the libsdp.log.##### temporary file.
Impact
Base Score 2.0
3.30
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:openfabrics:libsdp:*:*:*:*:*:*:*:* | 1.1.104 (including) | |
| cpe:2.3:a:openfabrics:libsdp:1.1.99:*:*:*:*:*:*:* | ||
| cpe:2.3:a:openfabrics:libsdp:1.1.100:*:*:*:*:*:*:* | ||
| cpe:2.3:a:openfabrics:libsdp:1.1.101:*:*:*:*:*:*:* | ||
| cpe:2.3:a:openfabrics:libsdp:1.1.102:*:*:*:*:*:*:* | ||
| cpe:2.3:a:openfabrics:libsdp:1.1.103:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.openfabrics.org/downloads/libsdp/libsdp-1.1.105-0.4.g1b9b996.tar.gz
- http://www.openwall.com/lists/oss-security/2010/11/16/2
- http://www.openwall.com/lists/oss-security/2010/11/16/7
- https://bugzilla.redhat.com/show_bug.cgi?id=647941
- http://www.openfabrics.org/downloads/libsdp/libsdp-1.1.105-0.4.g1b9b996.tar.gz
- http://www.openwall.com/lists/oss-security/2010/11/16/2
- http://www.openwall.com/lists/oss-security/2010/11/16/7
- https://bugzilla.redhat.com/show_bug.cgi?id=647941



