IBM AIX 'gssd' Kerberos Credential Cache Local Unauthorized Access Vulnerability
BID:36545
Info
IBM AIX 'gssd' Kerberos Credential Cache Local Unauthorized Access Vulnerability
| Bugtraq ID: | 36545 |
| Class: | Access Validation Error |
| CVE: |
CVE-2009-3516 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 29 2009 12:00AM |
| Updated: | Apr 13 2015 09:06PM |
| Credit: | Anton Lundin |
| Vulnerable: |
IBM AIX 6.1 IBM AIX 5.3 |
| Not Vulnerable: | |
Discussion
IBM AIX 'gssd' Kerberos Credential Cache Local Unauthorized Access Vulnerability
IBM AIX is prone to a local unauthorized-access vulnerability that affects the kernel's NFSv4 implementation.
Attackers can exploit this issue to access Kerberized network shares without proper authorization. This may lead to further attacks.
IBM AIX is prone to a local unauthorized-access vulnerability that affects the kernel's NFSv4 implementation.
Attackers can exploit this issue to access Kerberized network shares without proper authorization. This may lead to further attacks.
Exploit / POC
IBM AIX 'gssd' Kerberos Credential Cache Local Unauthorized Access Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
IBM AIX 'gssd' Kerberos Credential Cache Local Unauthorized Access Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for details.
IBM AIX 6.1
IBM AIX 5.3
Solution:
The vendor has released an advisory and updates. Please see the references for details.
IBM AIX 6.1
-
IBM nfs4_fix.tar
http://aix.software.ibm.com/aix/efixes/security/nfs4_fix.tar
IBM AIX 5.3
-
IBM nfs4_fix.tar
http://aix.software.ibm.com/aix/efixes/security/nfs4_fix.tar
References
IBM AIX 'gssd' Kerberos Credential Cache Local Unauthorized Access Vulnerability
References:
References: