IBM CTSTRTCASD Utility Local File Corruption Vulnerability

BID:11264

Info

IBM CTSTRTCASD Utility Local File Corruption Vulnerability

Bugtraq ID: 11264
Class: Access Validation Error
CVE: CVE-2004-0828
Remote: No
Local: Yes
Published: Sep 27 2004 12:00AM
Updated: Jul 12 2009 07:06AM
Credit: iDEFENSE Labs is credited with the discovery of this vulnerability.
Vulnerable: IBM Tivoli System Automation (TSA) for Multiplatforms 1.2
IBM Tivoli System Automation (TSA) for Linux 1.1
IBM Reliable Scalable Cluster Technology (RSCT) 2.3
IBM Hardware Management Console (HMC) for pSeries 4
IBM Hardware Management Console (HMC) for pSeries 3
IBM Hardware Management Console (HMC) for iSeries 4.0
IBM General Parallel File System (GPFS) Version 2 Release 2
IBM Cluster Systems Management (CSM) for Linux 1.4
IBM AIX 5.3 L
IBM AIX 5.2 L
Not Vulnerable:

Discussion

IBM CTSTRTCASD Utility Local File Corruption Vulnerability

It is reported that IBMs 'ctstrtcasd' utility is susceptible to a local file corruption vulnerability. This issue is due to a failure of the application to properly validate the permissions of the invoking user before overwriting a file specified by the user. This utility is setuid to the superuser, allowing for the overwriting of any file on affected computers, or the creation of files in any location.

As this vulnerability allows attackers to overwrite arbitrary files with superuser privileges, attackers have the ability to destroy data, or cause the computer to fail in such a manner that it will have to be reinstalled from backups. This will deny service to legitimate users.

RSCT versions 2.3.0.0 and higher running on AIX 5.2 and 5.3 on pSeries, AIX on i5/OS (iSeries), Linux (pSeries, xSeries, zSeries), and pSeries/iSeries Hardware Management Console are reported vulnerable.

Exploit / POC

IBM CTSTRTCASD Utility Local File Corruption Vulnerability

An exploit is not required.

Solution / Fix

IBM CTSTRTCASD Utility Local File Corruption Vulnerability

Solution:
IBM recommends that users should upgrade to the latest maintenance level of RSCT version 2.3 and 2.4. IBM plans to release fixes for various platforms. Users are advised to deploy the workarounds and contact the vendor for more information about specific fixes. Please see the referenced IBM advisory for detailed information.

References

IBM CTSTRTCASD Utility Local File Corruption Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report