IBM AIX LSPath Unauthorized Local File Disclosure Vulnerability
BID:12513
Info
IBM AIX LSPath Unauthorized Local File Disclosure Vulnerability
| Bugtraq ID: | 12513 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 10 2005 12:00AM |
| Updated: | Feb 10 2005 12:00AM |
| Credit: | Discovery is credited to iDEFENSE Labs. |
| Vulnerable: |
IBM AIX 5.3 IBM AIX 5.2 |
| Not Vulnerable: | |
Discussion
IBM AIX LSPath Unauthorized Local File Disclosure Vulnerability
A vulnerability exists in the IBM AIX lspath command that may allow for local file disclosure attacks. It is reported that this vulnerability may be exploited to read the first line (up to the first encounter white space) of an arbitrary file on the computer.
A vulnerability exists in the IBM AIX lspath command that may allow for local file disclosure attacks. It is reported that this vulnerability may be exploited to read the first line (up to the first encounter white space) of an arbitrary file on the computer.
Exploit / POC
IBM AIX LSPath Unauthorized Local File Disclosure Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
IBM AIX LSPath Unauthorized Local File Disclosure Vulnerability
Solution:
IBM has released an efix to address this issue. APARs for IBM AIX are pending release on 04/15/2005.
IBM AIX 5.2
IBM AIX 5.3
Solution:
IBM has released an efix to address this issue. APARs for IBM AIX are pending release on 04/15/2005.
IBM AIX 5.2
-
IBM IY67457
http://www-1.ibm.com/servers/eserver/support/pseries/aixfixes.html -
IBM IY67655
http://www-1.ibm.com/servers/eserver/support/pseries/aixfixes.html
IBM AIX 5.3
References
IBM AIX LSPath Unauthorized Local File Disclosure Vulnerability
References:
References: