IBM AIX libdiag Trace File Symlink Vulnerability
BID:8806
Info
IBM AIX libdiag Trace File Symlink Vulnerability
| Bugtraq ID: | 8806 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 10 2001 12:00AM |
| Updated: | Aug 10 2001 12:00AM |
| Credit: | This issue was reported by IBM. |
| Vulnerable: |
IBM AIX 5.1 |
| Not Vulnerable: | |
Discussion
IBM AIX libdiag Trace File Symlink Vulnerability
IBM libdiag is prone to symlink attacks when writing to trace files. Local attackers may potentially exploit this issue to cause critical system files to be corrupted, likely resulting in a denial of service. It is not known if this could be further exploited to elevate privileges.
IBM libdiag is prone to symlink attacks when writing to trace files. Local attackers may potentially exploit this issue to cause critical system files to be corrupted, likely resulting in a denial of service. It is not known if this could be further exploited to elevate privileges.
Exploit / POC
IBM AIX libdiag Trace File Symlink Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
IBM AIX libdiag Trace File Symlink Vulnerability
Solution:
This issue has been addressed by APAR IY22268, which is available to IBM AIX customers.
IBM AIX 5.1
Solution:
This issue has been addressed by APAR IY22268, which is available to IBM AIX customers.
IBM AIX 5.1
References
IBM AIX libdiag Trace File Symlink Vulnerability
References:
References: