OSVDB ID: 7998

Title: IBM AIX dump_smutil.sh Symlink Privilege Escalation

Info

Disclosure

Sep 26, 2002

Discovery

Sep 26, 2002

Dates

Exploit

Unknown

Solution

Unknown

Description

IBM AIX contains a flaw that may allow a malicious user to overwrite arbitrary files. The issue is triggered when the shell script dump_smutil.sh makes use of a file in /tmp which can point to critical system files. It is possible that the flaw may allow any file to be overwritten resulting in a loss of integrity.

Classification

Location: Local Access Required
Attack Type: Race Condition
Impact: Loss of Integrity
Exploit: Exploit Public
Disclosure: OSVDB Verified

Solution

Upgrade to version 4.3.3 (APAR IY34617), 5.1.0 (APAR IY33055), or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

International Business Machines Corporation

AIX

4.3.3
5.1.0

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/7998