PT-2005-4100 · Ibm · Aix
Published
2005-10-23
·
Updated
2008-09-05
·
CVE-2005-3289
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM AIX versions 5.2 through 5.3
Description
The issue allows local users to corrupt system files, including /etc/passwd, by exploiting insecure temporary file creation in LSCFG. This can potentially lead to system compromise.
Recommendations
For IBM AIX versions 5.2 through 5.3, consider restricting access to LSCFG to minimize the risk of exploitation until a secure method of temporary file creation is implemented.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aix