CVE Vulnerabilities

CVE-1999-1405

Published: Feb 17, 1999 | Modified: Oct 18, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.

Affected Software

Name Vendor Start Version End Version
Aix Ibm 3.2.5 (including) 3.2.5 (including)
Aix Ibm 4.1 (including) 4.1 (including)
Aix Ibm 4.1.2 (including) 4.1.2 (including)
Aix Ibm 4.1.3 (including) 4.1.3 (including)
Aix Ibm 4.1.4 (including) 4.1.4 (including)
Aix Ibm 4.1.5 (including) 4.1.5 (including)
Aix Ibm 4.2 (including) 4.2 (including)
Aix Ibm 4.2.1 (including) 4.2.1 (including)

References