Vulnerabilities > CVE-1999-1405 - Unspecified vulnerability in IBM AIX

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
ibm
critical
exploit available

Summary

snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a. Fixed in AIX 4.3 and 4.3.2 AIX 4.3.x APAR: IX88263 AIX 4.2.x APAR: IX88261

Exploit-Db

descriptionIBM AIX 4.2.1 snap Insecure Temporary File Creation Vulnerability. CVE-1999-1405. Local exploit for aix platform
idEDB-ID:19300
last seen2016-02-02
modified1999-02-17
published1999-02-17
reporterLarry W. Cashdollar
sourcehttps://www.exploit-db.com/download/19300/
titleIBM AIX <= 4.2.1 snap Insecure Temporary File Creation Vulnerability