IBM AIX CVE-2014-3074 Temporary File Creation Vulnerability
BID:68296
Info
IBM AIX CVE-2014-3074 Temporary File Creation Vulnerability
| Bugtraq ID: | 68296 |
| Class: | Design Error |
| CVE: |
CVE-2014-3074 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 30 2014 12:00AM |
| Updated: | Jul 08 2014 05:08PM |
| Credit: | Tim Brown from Portcullis Computer Security Ltd. |
| Vulnerable: |
IBM AIX 7.1 IBM AIX 6.1 |
| Not Vulnerable: | |
Discussion
IBM AIX CVE-2014-3074 Temporary File Creation Vulnerability
IBM AIX is prone to a vulnerability because it creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files which may result in a denial of service or gaining elevated privileges on the affected computer.
IBM AIX 6.1 and 7.1 are vulnerable.
IBM AIX is prone to a vulnerability because it creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files which may result in a denial of service or gaining elevated privileges on the affected computer.
IBM AIX 6.1 and 7.1 are vulnerable.
Exploit / POC
IBM AIX CVE-2014-3074 Temporary File Creation Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
IBM AIX CVE-2014-3074 Temporary File Creation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.