OSVDB ID: 7921

Title: IBM AIX Multiple LVM Commands Unspecified Symlink File Overwrite

Info

Disclosure

Mar 22, 2004

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

IBM AIX contains a flaw that may allow a malicious user to abuse LVM commands to overwrite arbitrary files. The issue is triggered when an attacker uses symlinks to point to arbitrary files. It is possible that the flaw may allow the writing or overwriting of critical files resulting in a loss of confidentiality, and/or integrity.

Classification

Location: Local Access Required
Attack Type: Race Condition
Impact: Loss of Integrity, Loss of Availability
Exploit: Exploit Unknown
Disclosure: OSVDB Verified

Solution

Upgrade AIX using the APAR numbers AIX 5.1.0:  IY55681 and AIX 5.2.0:  IY55682 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

International Business Machines Corporation

AIX

4.3.3
5.1.0
5.2.0

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/7921