IBM AIX '_LIB_INIT_DBG' and '_LIB_INIT_DBG_FILE' File Creation Vulnerability
BID:35934
Info
IBM AIX '_LIB_INIT_DBG' and '_LIB_INIT_DBG_FILE' File Creation Vulnerability
| Bugtraq ID: | 35934 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 04 2009 12:00AM |
| Updated: | Sep 11 2009 09:01PM |
| Credit: | Karol Wiesek |
| Vulnerable: |
IBM AIX 6.1 IBM AIX 5.3 |
| Not Vulnerable: | |
Discussion
IBM AIX '_LIB_INIT_DBG' and '_LIB_INIT_DBG_FILE' File Creation Vulnerability
IBM AIX is prone to multiple file-creation vulnerabilities.
An attacker with local access can exploit these issues to create and execute arbitrary files with superuser privileges. Successful exploits will completely compromise affected computers.
AIX 5.3 and 6.1 are vulnerable.
IBM AIX is prone to multiple file-creation vulnerabilities.
An attacker with local access can exploit these issues to create and execute arbitrary files with superuser privileges. Successful exploits will completely compromise affected computers.
AIX 5.3 and 6.1 are vulnerable.
Exploit / POC
IBM AIX '_LIB_INIT_DBG' and '_LIB_INIT_DBG_FILE' File Creation Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
IBM AIX '_LIB_INIT_DBG' and '_LIB_INIT_DBG_FILE' File Creation Vulnerability
Solution:
The vendor has released an update. Please see the references for details.
IBM AIX 6.1
IBM AIX 5.3
Solution:
The vendor has released an update. Please see the references for details.
IBM AIX 6.1
-
IBM libC_fix.tar
http://aix.software.ibm.com/aix/efixes/security/libC_fix.tar
IBM AIX 5.3
-
IBM libC_fix.tar
http://aix.software.ibm.com/aix/efixes/security/libC_fix.tar
References
IBM AIX '_LIB_INIT_DBG' and '_LIB_INIT_DBG_FILE' File Creation Vulnerability
References:
References: