IBM policyd and rsvpd Insecure Temporary File Creation Vulnerability
BID:8808
Info
IBM policyd and rsvpd Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 8808 |
| Class: | Design Error |
| CVE: | |
| Remote: | Unknown |
| Local: | Unknown |
| Published: | Apr 04 2002 12:00AM |
| Updated: | Apr 04 2002 12:00AM |
| Credit: | The disclosure of this issue has been credited to the vendor. |
| Vulnerable: |
IBM AIX 5.1 |
| Not Vulnerable: | |
Discussion
IBM policyd and rsvpd Insecure Temporary File Creation Vulnerability
It has been reported that policyd and rsvpd daemons are prone to an insecure file creation vulnerability that may allow an attacker to use symbolic links to corrupt system files or potentially gain elevated privileges. The problem arises as the daemons create log files and pid files in world readable format without checking for symbolic links.
Successful exploitation of this issue may allow an attacker to create or modify arbitrary files. This may lead to a denial of service due to system file corruption or allow an attacker to gain elevated privileges.
AIX 5.1 has been reported to be vulnerable to this issue, although unconfirmed other versions may be affected as well.
It has been reported that policyd and rsvpd daemons are prone to an insecure file creation vulnerability that may allow an attacker to use symbolic links to corrupt system files or potentially gain elevated privileges. The problem arises as the daemons create log files and pid files in world readable format without checking for symbolic links.
Successful exploitation of this issue may allow an attacker to create or modify arbitrary files. This may lead to a denial of service due to system file corruption or allow an attacker to gain elevated privileges.
AIX 5.1 has been reported to be vulnerable to this issue, although unconfirmed other versions may be affected as well.
Exploit / POC
IBM policyd and rsvpd Insecure Temporary File Creation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
IBM policyd and rsvpd Insecure Temporary File Creation Vulnerability
Solution:
The vendor has released a fix (AIX 5L POWER 5765E6100) to address this issue:
IBM AIX 5.1
Solution:
The vendor has released a fix (AIX 5L POWER 5765E6100) to address this issue:
IBM AIX 5.1
References
IBM policyd and rsvpd Insecure Temporary File Creation Vulnerability
References:
References: