LSCFG in IBM AIX 5.2 and 5.3 does not create temporary files securely, which allows local users to corrupt /etc/passwd and possibly other system files via the trace file.
Link | Tags |
---|---|
http://www-1.ibm.com/support/docview.wss?uid=isg1IY77624 | vendor advisory |
http://securitytracker.com/id?1015061 | vdb entry |
http://secunia.com/advisories/17202 | third party advisory |
http://www-1.ibm.com/support/docview.wss?uid=isg1IY77638 | vendor advisory |
http://www.securityfocus.com/bid/15105 | vdb entry |