PT-2014-5650 · Ibm · Ibm Aix+1
Publicado
2014-06-08
·
Atualizado
2021-08-31
·
CVE-2014-3977
CVSS v2.0
6.9
Média
| Vetor | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM AIX versions 6.1 and 7.1
VIOS versions 2.2.x
Description
The issue allows local users to overwrite arbitrary files via a symlink attack on a temporary file. This is due to an incomplete fix for a previous issue.
Recommendations
For IBM AIX versions 6.1 and 7.1, consider restricting access to the
libodm.a library until a patch is available.
For VIOS versions 2.2.x, restrict access to the libodm.a library until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Link Following
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Aix
Vios