IBM AIX 'rmsock' Insecure Log File Handling Vulnerability
BID:33522
Info
IBM AIX 'rmsock' Insecure Log File Handling Vulnerability
| Bugtraq ID: | 33522 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 29 2009 12:00AM |
| Updated: | Jan 30 2009 04:19PM |
| Credit: | This issue was disclosed by the vendor. |
| Vulnerable: |
IBM AIX 6.1.2 IBM AIX 6.1.1 IBM AIX 5.3.9 IBM AIX 5.3.8 IBM AIX 5.3.7 IBM AIX 5.3 L IBM AIX 5.2.2 IBM AIX 5.2 L IBM AIX 6.1 IBM AIX 5.3 IBM AIX 5.2 |
| Not Vulnerable: | |
Discussion
IBM AIX 'rmsock' Insecure Log File Handling Vulnerability
IBM AIX 'rmsock' and 'rmsock64' handle log files in an insecure manner.
An attacker with local access could exploit this issue to append data to arbitrary files, which may result in privilege escalation or cause a denial-of-service condition. Other attacks may also be possible.
AIX 5.2, 5.3, and 6.1 are vulnerable; other versions may also be affected.
IBM AIX 'rmsock' and 'rmsock64' handle log files in an insecure manner.
An attacker with local access could exploit this issue to append data to arbitrary files, which may result in privilege escalation or cause a denial-of-service condition. Other attacks may also be possible.
AIX 5.2, 5.3, and 6.1 are vulnerable; other versions may also be affected.
Exploit / POC
IBM AIX 'rmsock' Insecure Log File Handling Vulnerability
Attackers can exploit this issue with readily available command-line tools.
Attackers can exploit this issue with readily available command-line tools.
Solution / Fix
IBM AIX 'rmsock' Insecure Log File Handling Vulnerability
Solution:
Vendor updates are available; please see the references for more information.
IBM AIX 6.1
IBM AIX 5.2
IBM AIX 5.3
IBM AIX 5.2 L
IBM AIX 5.2.2
IBM AIX 5.3 L
IBM AIX 5.3.7
IBM AIX 5.3.8
IBM AIX 5.3.9
IBM AIX 6.1.1
IBM AIX 6.1.2
Solution:
Vendor updates are available; please see the references for more information.
IBM AIX 6.1
-
IBM rmsock_fix.tar
http://aix.software.ibm.com/aix/efixes/security/rmsock_fix.tar
IBM AIX 5.2
-
IBM rmsock_fix.tar
http://aix.software.ibm.com/aix/efixes/security/rmsock_fix.tar
IBM AIX 5.3
-
IBM rmsock_fix.tar
http://aix.software.ibm.com/aix/efixes/security/rmsock_fix.tar
IBM AIX 5.2 L
-
IBM rmsock_fix.tar
http://aix.software.ibm.com/aix/efixes/security/rmsock_fix.tar
IBM AIX 5.2.2
-
IBM rmsock_fix.tar
http://aix.software.ibm.com/aix/efixes/security/rmsock_fix.tar
IBM AIX 5.3 L
-
IBM rmsock_fix.tar
http://aix.software.ibm.com/aix/efixes/security/rmsock_fix.tar
IBM AIX 5.3.7
-
IBM rmsock_fix.tar
http://aix.software.ibm.com/aix/efixes/security/rmsock_fix.tar
IBM AIX 5.3.8
-
IBM rmsock_fix.tar
http://aix.software.ibm.com/aix/efixes/security/rmsock_fix.tar
IBM AIX 5.3.9
-
IBM rmsock_fix.tar
http://aix.software.ibm.com/aix/efixes/security/rmsock_fix.tar
IBM AIX 6.1.1
-
IBM rmsock_fix.tar
http://aix.software.ibm.com/aix/efixes/security/rmsock_fix.tar
IBM AIX 6.1.2
-
IBM rmsock_fix.tar
http://aix.software.ibm.com/aix/efixes/security/rmsock_fix.tar
References
IBM AIX 'rmsock' Insecure Log File Handling Vulnerability
References:
References:
- AIX Homepage (IBM)
- AIX rmsock log append file vulnerability (IBM)