|
IBM AIX contains a flaw that may allow a malicious local user to manipulate arbitrary files on the system. The issue is due to the /usr/sbin/fibred script creating temporary files insecurely. It is possible for a local attacker to use a symlink attack against the /usr/sbin/fibred.log file to cause the program to unexpectedly write to, or overwrite an attacker specified file. This may allow an attacker to gain escalated privileges
|