Back to search
CVE-2007-5804
Published: Nov 5, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
cfgcon in IBM AIX 5.2 and 5.3 does not properly validate the argument to the "-p" option to swcons, which allows local users in the system group to create or overwrite an arbitrary file, and enable world writability of this file, by using the file's name as the argument.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
aix-swcons-insecure-permissions(38154)
vdb-entry
x_refsource_XF
27437
third-party-advisory
x_refsource_SECUNIA
26258
vdb-entry
x_refsource_BID
IZ03055
vendor-advisory
x_refsource_AIXAPAR
IZ03061
vendor-advisory
x_refsource_AIXAPAR
20071030 IBM AIX swcons Local Arbitrary File Access Vulnerability
third-party-advisory
x_refsource_IDEFENSE
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now