CVE-2008-4018
Summary
| CVE | CVE-2008-4018 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-09-11 01:13:52 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | swcons in bos.rte.console in IBM AIX 5.2.0 through 6.1.1 allows local users in the system group to create or overwrite an arbitrary file, and establish weak permissions and root ownership for this file, via unspecified vectors. NOTE: this can be leveraged to gain privileges. NOTE: this issue exists because of an incomplete fix for CVE-2007-5805. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM IZ18341: SYSTEM GROUP USERS CAN CREATE/MODIFY FILES REGARDLESS OF PERMS APPLIES TO AIX 6100-00 - United States | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | |
| IBM AIX 'swcons' Insecure File Creation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | |
| aix.software.ibm.com/aix/efixes/security/swcons_advisory.asc | af854a3a-2127-422b-91ae-364da2661108 | aix.software.ibm.com | |
| IBM IZ18338: SYSTEM GROUP USERS CAN CREATE/MODIFY FILES REGARDLESS OF PERMS APPLIES TO AIX 5300-07 - United States | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | |
| IBM AIX "swcons" Command Privilege Escalation Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| IBM AIX swcons Bug Lets Local Users Gain Root Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| IBM IZ28943: SYSTEM GROUP USERS CAN CREATE/MODIFY FILES REGARDLESS OF PERMS APPLIES TO AIX 6100-01 - United States | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.