ubuntu · CVE-2011-3345

Quick triage

Priority: low Published: 2011-09-19 12:02:00 UTC Updated: 2024-07-24 15:57:39 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2011-3345 low priority: Ubuntu including 7 source packages (linux, linux-ec2, …), 35 status rows across 5 suites (hardy, lucid, maverick, natty, upstream): not-affected 19, DNE 15, ignored 1.

Description:

ulp/sdp/sdp_proc.c in the ib_sdp module (aka ib_sdp.ko) in the ofa_kernel package in the InfiniBand driver implementation in OpenFabrics Enterprise Distribution (OFED) before 1.5.3 does not properly handle certain non-array variables, which allows local users to cause a denial of service (stack memory corruption and system crash) by reading the /proc/net/sdpstats file.

cvelogic Threat Intelligence