AIX vi(1) Insecure Temporary File Creation Vulnerability
BID:444
Info
AIX vi(1) Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 444 |
| Class: | Origin Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 28 1998 12:00AM |
| Updated: | Jul 28 1998 12:00AM |
| Credit: | This vulnerability was published to the IBM APAR Database on July 28, 1998. The SecurityFocus Database entry for this problem is based wholly off that information. |
| Vulnerable: |
IBM AIX 4.3 IBM AIX 4.2.1 IBM AIX 4.2 IBM AIX 4.1.5 IBM AIX 4.1.4 IBM AIX 4.1.3 IBM AIX 4.1.2 IBM AIX 4.1.1 IBM AIX 4.1 |
| Not Vulnerable: |
IBM AIX 4.3.2 |
Discussion
AIX vi(1) Insecure Temporary File Creation Vulnerability
The vi(1) program under certain versions of AIX will follow symlinks when creating /var/tmp/Ex* temp files. This allows malicous users to symlink to these files and overwrite other system files at the privilege level of the user executing the program.
The vi(1) program under certain versions of AIX will follow symlinks when creating /var/tmp/Ex* temp files. This allows malicous users to symlink to these files and overwrite other system files at the privilege level of the user executing the program.
Exploit / POC
AIX vi(1) Insecure Temporary File Creation Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
References
AIX vi(1) Insecure Temporary File Creation Vulnerability
References:
References:
- AIX Fix Distribution Service (IBM)
- IBM Support Databases (IBM)