IBM AIX RDIST Local Arbitrary File Overwrite Vulnerability
BID:20194
Info
IBM AIX RDIST Local Arbitrary File Overwrite Vulnerability
| Bugtraq ID: | 20194 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 25 2006 12:00AM |
| Updated: | Sep 26 2006 05:01PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
IBM AIX 5.3 L IBM AIX 5.2 L IBM AIX 5.3 IBM AIX 5.2 |
| Not Vulnerable: | |
Discussion
IBM AIX RDIST Local Arbitrary File Overwrite Vulnerability
IBM AIX is prone to a local a local arbitrary file-overwrite vulnerability.
A local attacker can exploit this issue to overwrite arbitrary files. This may result in denial-of-service conditions or permit an attacker to take complete control of a vulnerable computer.
This issue pertains only to '/usr/bin/rdist'; '/usr/sbin/rdist' is not affected.
IBM AIX versions 5.2 and 5.3 are vulnerable to this issue.
IBM AIX is prone to a local a local arbitrary file-overwrite vulnerability.
A local attacker can exploit this issue to overwrite arbitrary files. This may result in denial-of-service conditions or permit an attacker to take complete control of a vulnerable computer.
This issue pertains only to '/usr/bin/rdist'; '/usr/sbin/rdist' is not affected.
IBM AIX versions 5.2 and 5.3 are vulnerable to this issue.
Exploit / POC
IBM AIX RDIST Local Arbitrary File Overwrite Vulnerability
Currently we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
IBM AIX RDIST Local Arbitrary File Overwrite Vulnerability
Solution:
IBM has released an advisory and interim fixes to address this issue. Please see the references for more information.
IBM AIX 5.2
IBM AIX 5.3
IBM AIX 5.2 L
IBM AIX 5.3 L
Solution:
IBM has released an advisory and interim fixes to address this issue. Please see the references for more information.
IBM AIX 5.2
-
IBM rdist_ifix.tar.Z
ftp://aix.software.ibm.com/aix/efixes/security/rdist_ifix.tar.Z -
IBM IY88688
http://www-1.ibm.com/support/docview.wss?uid=isg1IY88688
IBM AIX 5.3
-
IBM rdist_ifix.tar.Z
ftp://aix.software.ibm.com/aix/efixes/security/rdist_ifix.tar.Z -
IBM IY88687
http://www-1.ibm.com/support/docview.wss?uid=isg1IY88687
IBM AIX 5.2 L
-
IBM rdist_ifix.tar.Z
ftp://aix.software.ibm.com/aix/efixes/security/rdist_ifix.tar.Z
IBM AIX 5.3 L
-
IBM rdist_ifix.tar.Z
ftp://aix.software.ibm.com/aix/efixes/security/rdist_ifix.tar.Z