IBM U2 UniVerse cci_dir Insecure Filesystem Links Vulnerability
BID:8202
Info
IBM U2 UniVerse cci_dir Insecure Filesystem Links Vulnerability
| Bugtraq ID: | 8202 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 16 2003 12:00AM |
| Updated: | Jul 16 2003 12:00AM |
| Credit: | Reported by KF <[email protected]>. |
| Vulnerable: |
IBM UniVerse 10.0 .0.9 |
| Not Vulnerable: | |
Discussion
IBM U2 UniVerse cci_dir Insecure Filesystem Links Vulnerability
It has been reported that IBM UniVerse may not properly create filesystem links. Attackers may be able to take advantage of the insecure usage of linking functions to create and delete files. Because the vulnerable binary is installed with suid root privileges, unprivileged users may perform these operations with elevated privileges.
While this vulnerability was reported in UniVerse version 10.0.0.9, previous versions are likely vulnerable as well.
It has been reported that IBM UniVerse may not properly create filesystem links. Attackers may be able to take advantage of the insecure usage of linking functions to create and delete files. Because the vulnerable binary is installed with suid root privileges, unprivileged users may perform these operations with elevated privileges.
While this vulnerability was reported in UniVerse version 10.0.0.9, previous versions are likely vulnerable as well.
Exploit / POC
IBM U2 UniVerse cci_dir Insecure Filesystem Links Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
IBM U2 UniVerse cci_dir Insecure Filesystem Links Vulnerability
Solution:
The discoverer of this issue has reported that fixes are pending. Users should contact the vendor for further details.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The discoverer of this issue has reported that fixes are pending. Users should contact the vendor for further details.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.