PT-2009-5808 · Ibm · Ibm Aix
Anton Lundin
·
Published
2009-10-01
·
Updated
2017-09-19
·
CVE-2009-3516
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM AIX versions 5.3.x through 5.3.9
IBM AIX versions 6.1.0 through 6.1.2
Description
The issue is related to the handling of the NFSv4 Kerberos credential cache by gssd in IBM AIX. This improper handling allows local users to bypass intended access restrictions for Kerberized NFSv4 shares.
Recommendations
For IBM AIX versions 5.3.x through 5.3.9, update to a version that properly handles the NFSv4 Kerberos credential cache.
For IBM AIX versions 6.1.0 through 6.1.2, update to a version that properly handles the NFSv4 Kerberos credential cache.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Aix