IBM AIX Inventory Scout Local Arbitrary File Overwrite Vulnerability
BID:20199
CVE-2006-5002 |Info
IBM AIX Inventory Scout Local Arbitrary File Overwrite Vulnerability
| Bugtraq ID: | 20199 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 25 2006 12:00AM |
| Updated: | Sep 26 2006 09:36PM |
| Credit: | The vendor has disclosed this issue. |
| Vulnerable: |
IBM AIX 5.3 IBM AIX 5.2 |
| Not Vulnerable: | |
Discussion
IBM AIX Inventory Scout Local Arbitrary File Overwrite Vulnerability
IBM AIX Inventory Scout is prone to a local arbitrary-file-overwrite vulnerability.
A local attacker may be able to exploit this issue to overwrite arbitrary files and corrupt sensitive data, which could lead to denial-of-service conditions. Privilege-escalation attacks may be possible as well.
IBM Inventory Scout 2.2 for AIX versions 5.2 and 5.3 is vulnerable to this issue.
IBM AIX Inventory Scout is prone to a local arbitrary-file-overwrite vulnerability.
A local attacker may be able to exploit this issue to overwrite arbitrary files and corrupt sensitive data, which could lead to denial-of-service conditions. Privilege-escalation attacks may be possible as well.
IBM Inventory Scout 2.2 for AIX versions 5.2 and 5.3 is vulnerable to this issue.
Exploit / POC
IBM AIX Inventory Scout Local Arbitrary File Overwrite Vulnerability
Currently we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
IBM AIX Inventory Scout Local Arbitrary File Overwrite Vulnerability
Solution:
IBM has released an advisory and interim fixes to address this issue. Please see the references for more information.
IBM AIX 5.2
IBM AIX 5.3
Solution:
IBM has released an advisory and interim fixes to address this issue. Please see the references for more information.
IBM AIX 5.2
-
IBM invscoutClient_VPD_Survey.tar.Z
ftp://aix.software.ibm.com/aix/efixes/security/invscoutClient_VPD_Surv ey.tar.Z -
IBM IY88735 AIX 5.2
http://www-03.ibm.com/servers/eserver/support/unixservers/aixfixes.htm l -
IBM IY88735 AIX 5.3
http://www-03.ibm.com/servers/eserver/support/unixservers/aixfixes.htm l
IBM AIX 5.3
-
IBM invscoutClient_VPD_Survey.tar.Z
ftp://aix.software.ibm.com/aix/efixes/security/invscoutClient_VPD_Surv ey.tar.Z -
IBM IY88735 AIX 5.2
http://www-03.ibm.com/servers/eserver/support/unixservers/aixfixes.htm l -
IBM IY88735 AIX 5.3
http://www-03.ibm.com/servers/eserver/support/unixservers/aixfixes.htm l
References
IBM AIX Inventory Scout Local Arbitrary File Overwrite Vulnerability
References:
References:
- AIX Fixes (IBM)
- AIX Homepage (IBM)