|
|

CVE Reference: CVE-2007-5804 |
|
| NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE. | |
|
Original Page at CVE MITRE: CVE-2007-5804 |
|
|
Description: cfgcon in IBM AIX 5.2 and 5.3 does not properly validate the argument to the "-p" option to swcons, which allows local users in the system group to create or overwrite an arbitrary file, and enable world writability of this file, by using the file's name as the argument. |
|
|
CVE Status: Candidate |
|
|
References: XF http://xforce.iss.net/xforce/xfdb/38154 SAID Secunia Advisory: SA27437 IDEFENSE http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=611 CONFIRM http://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&heading=AIX53&path=%2F200710%2FSECURITY%2F20071030%2Fdatafile100405 BID 26258 AIXAPAR http://www-1.ibm.com/support/docview.wss?uid=isg1IZ03055 http://www-1.ibm.com/support/docview.wss?uid=isg1IZ03061 |
|
| Return to the previous page. |
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |