Title: IBM AIX dump_smutil.sh Symlink Privilege Escalation
Info
Disclosure
Sep 26, 2002
Discovery
Sep 26, 2002
Dates
Exploit
Unknown
Solution
Unknown
Description
IBM AIX contains a flaw that may allow a malicious user to overwrite arbitrary files. The issue is triggered when the shell script dump_smutil.sh makes use of a file in /tmp which can point to critical system files. It is possible that the flaw may allow any file to be overwritten resulting in a loss of integrity.
Classification
Location:
Local Access Required
Attack Type:
Race Condition
Impact:
Loss of Integrity
Exploit:
Exploit Public
Disclosure:
OSVDB Verified
Solution
Upgrade to version 4.3.3 (APAR IY34617), 5.1.0 (APAR IY33055), or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.