IBM AIX Temporary File Creation Vulnerability
BID:54122
Info
IBM AIX Temporary File Creation Vulnerability
| Bugtraq ID: | 54122 |
| Class: | Design Error |
| CVE: |
CVE-2014-3977 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 21 2012 12:00AM |
| Updated: | Mar 19 2015 08:45AM |
| Credit: | Jakub Wartak |
| Vulnerable: |
IBM AIX 7.1 IBM AIX 6.1 IBM AIX 5.3 |
| Not Vulnerable: | |
Discussion
IBM AIX Temporary File Creation Vulnerability
IBM AIX is prone to a vulnerability because it creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files which may result in a denial of service or gaining elevated privileges on the affected computer.
IBM AIX versions 5.3, 6.1, and 7.1 are vulnerable.
IBM AIX is prone to a vulnerability because it creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files which may result in a denial of service or gaining elevated privileges on the affected computer.
IBM AIX versions 5.3, 6.1, and 7.1 are vulnerable.
Exploit / POC
IBM AIX Temporary File Creation Vulnerability
An attacker can use readily available commands to exploit this issue.
An attacker can use readily available commands to exploit this issue.
Solution / Fix
IBM AIX Temporary File Creation Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
IBM AIX Temporary File Creation Vulnerability
References:
References: