AIX crontab Vulnerability
BID:357
Info
AIX crontab Vulnerability
| Bugtraq ID: | 357 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 05 1992 12:00AM |
| Updated: | Mar 05 1992 12:00AM |
| Credit: | This bug was released as CERT advisory CA-92.10 AIX Crontab Vulnerability. |
| Vulnerable: |
IBM AIX 3.2 IBM AIX 3.1 IBM AIX 2.2.1 IBM AIX 1.3 IBM AIX 1.2.1 |
| Not Vulnerable: |
IBM AIX 4.3 IBM AIX 4.2.1 IBM AIX 4.2 IBM AIX 4.1.5 IBM AIX 4.1.4 IBM AIX 4.1.3 IBM AIX 4.1.2 IBM AIX 4.1.1 IBM AIX 4.1 IBM AIX 3.2.5 IBM AIX 3.2.4 |
Discussion
AIX crontab Vulnerability
The /usr/bin/crontab which shipped with AIX version 3.2 was apparently open to local user attack which could lead to root privelages. The CERT advisory which was issued on this subject was rather vague and gave no details as to what the problem was precisely.
The /usr/bin/crontab which shipped with AIX version 3.2 was apparently open to local user attack which could lead to root privelages. The CERT advisory which was issued on this subject was rather vague and gave no details as to what the problem was precisely.
Exploit / POC
AIX crontab Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
AIX crontab Vulnerability
Solution:
IBM issued the following APAR to deal with this problem:
APAR # ix26997
Solution:
IBM issued the following APAR to deal with this problem:
APAR # ix26997
References
AIX crontab Vulnerability
References:
References:
- AIX Fix Distribution Service (IBM)
- IBM Support Databases (IBM)