snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:31
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=91936783009385&w=2 - | |
References | () http://marc.info/?l=bugtraq&m=91954824614013&w=2 - | |
References | () http://www.securityfocus.com/bid/375 - Exploit |
Information
Published : 1999-02-17 05:00
Updated : 2024-11-20 23:31
NVD link : CVE-1999-1405
Mitre link : CVE-1999-1405
CVE.ORG link : CVE-1999-1405
JSON object : View
Products Affected
ibm
- aix
CWE