|
Brought to you by:
Suppliers of:
|
|
|
| |
| Local exploitation of a file overwrite vulnerability in IBM Corp.'s Advanced Interactive eXecutive (AIX) could allow an attacker to overwrite arbitrary files and execute arbitrary code. |
| |
Credit:
The information has been provided by Anonymous.
The original article can be found at: http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=802
|
| |
Vulnerable Systems:
* IBM AIX version 5.3
The AIX libc implementation of malloc includes a debugging mechanism that is initiated by setting the MALLOCTYPE and MALLOCDEBUG environment variables. This debugging feature writes to a user-specified log file under certain conditions. There is a gap in time between the checks to see if the file is a symbolic link and the process of opening the file. If an attacker can change the file to be a symbolic link to another file within this time frame, it is possible to cause a set-uid binary to write to files owned by privileged users.
Patch Availability:
http://aix.software.ibm.com/aix/efixes/security/libc_advisory.asc
or
ftp://aix.software.ibm.com/aix/efixes/security/libc_advisory.asc
Disclosure Timeline:
01/05/2008 - PoC Requested
12/16/2008 - Initial Response
12/16/2008 - Initial notification
01/06/2009 - PoC Sent
05/19/2009 - Coordinated public Disclosure
|
|
|
|
|