Beveiligingsadvies

CVE-2007-5805

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2007-11-05 17:00:00
Laatst bijgewerkt 2024-08-07 15:47:00
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

cfgcon in IBM AIX 5.2 and 5.3 does not properly validate the argument to the "-p" option to swcons, which allows local users in the system group to create an arbitrary file, and enable world writability of this file, via a symlink attack involving use of the file's name as the argument. NOTE: this issue is due to an incomplete fix for CVE-2007-5804.