cfgcon in IBM AIX 5.2 and 5.3 does not properly...
Vulnerability Description
cfgcon in IBM AIX 5.2 and 5.3 does not properly validate the argument to the "-p" option to swcons, which allows local users in the system group to create or overwrite an arbitrary file, and enable world writability of this file, by using the file's name as the argument.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-5804
Credits & Attribution
No credits recorded in the NVD database.
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38154
- http://secunia.com/advisories/27437
- http://www.securityfocus.com/bid/26258
- http://www-1.ibm.com/support/docview.wss?uid=isg1IZ03055
- ftp://aix.software.ibm.com/aix/efixes/security/cfgcon_ifix.tar
- http://www-1.ibm.com/support/docview.wss?uid=isg1IZ03061
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=611
- http://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&heading=AIX53&path=%2F200710%2FSECURITY%2F20071030%2Fdatafile100405
More from ibm
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.