IBM dump_smutil.sh Insecure Temporary File Creation Vulnerability
BID:8802
Info
IBM dump_smutil.sh Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 8802 |
| Class: | Design Error |
| CVE: |
CVE-2002-1550 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 26 2002 12:00AM |
| Updated: | Jul 11 2009 11:56PM |
| Credit: | This vulnerability was reported by IBM. |
| Vulnerable: |
IBM AIX 4.3.3 IBM AIX 5.1 |
| Not Vulnerable: | |
Discussion
IBM dump_smutil.sh Insecure Temporary File Creation Vulnerability
IBM has reported that the AIX dump_smutil.sh utility may be prone to symlink attacks due to insecure temporary file creation. The precise details regarding this issue are currently unknown, however it is likely that during a specific operation the affected utility places a filename in a world accessible directory using a predictable name. As a result, an attacker may be capable of overwriting an arbitrary system file with the privileges of the utility.
IBM has reported that the AIX dump_smutil.sh utility may be prone to symlink attacks due to insecure temporary file creation. The precise details regarding this issue are currently unknown, however it is likely that during a specific operation the affected utility places a filename in a world accessible directory using a predictable name. As a result, an attacker may be capable of overwriting an arbitrary system file with the privileges of the utility.
Exploit / POC
IBM dump_smutil.sh Insecure Temporary File Creation Vulnerability
This issue can be exploited through the creation of a malicious symbolic link.
This issue can be exploited through the creation of a malicious symbolic link.
References
IBM dump_smutil.sh Insecure Temporary File Creation Vulnerability
References:
References:
- IY33055: SECURITY: INSECURE TEMPORARY FILE CREATED BY DUMP_SMUTIL.SH (IBM)
- MSS-OAR-E01-2002:1117.1 (IBM Global Services)