The default configuration of libsdp.conf in libsdp 1.1.104 and earlier creates log files in /tmp, which allows local users to overwrite arbitrary files via a (1) symlink or (2) hard link attack on the libsdp.log.##### temporary file.
2010-11-22T20:00:03.980
2025-04-11T00:51:21.963
Deferred
CVSSv2: 3.3 (LOW)
AV:L/AC:M/Au:N/C:N/I:P/A:P
3.4
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openfabrics | libsdp | ≤ 1.1.104 | Yes |
Application | openfabrics | libsdp | 1.1.99 | Yes |
Application | openfabrics | libsdp | 1.1.100 | Yes |
Application | openfabrics | libsdp | 1.1.101 | Yes |
Application | openfabrics | libsdp | 1.1.102 | Yes |
Application | openfabrics | libsdp | 1.1.103 | Yes |