PT-2007-6769 · Ibm · Ibm Aix

Published

2007-11-05

·

Updated

2017-07-29

·

CVE-2007-5804

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM AIX versions 5.2 through 5.3
Description The issue allows local users in the system group to create or overwrite an arbitrary file and enable world writability of this file by using the file's name as the argument to the "-p" option in swcons.
Recommendations For IBM AIX versions 5.2 through 5.3, consider restricting access to the swcons command and the cfgcon utility to prevent unauthorized file creation or modification. As a temporary workaround, consider disabling the use of the "-p" option in swcons until a proper fix is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-5804

Affected Products

Ibm Aix