Vulnerability Name: | CVE-2007-6680 (CCN-39338) | ||||||||
Assigned: | 2007-12-27 | ||||||||
Published: | 2007-12-27 | ||||||||
Updated: | 2011-03-08 | ||||||||
Summary: | Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call to the trustchk_block_write function, which might allow local users to modify trusted files, related to an error in the support for links in the TSD_FILES_LOCK policy. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N) 1.6 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
1.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-6680 Source: CCN Type: SA28257 IBM AIX Trusted Execution Vulnerability Source: SECUNIA Type: Vendor Advisory 28257 Source: CCN Type: SECTRACK ID: 1019158 IBM AIX Trusted Execution Bug Has Unspecified Impact Source: CCN Type: IBM APAR IZ12119 TSD_FILES_LOCK DOES NOT WORK FOR LINKS Source: CCN Type: IBM APAR IZ12118 TSD_FILES_LOCK DOES NOT WORK FOR LINKS Source: CCN Type: IBM APAR IZ13418 TSD_FILES_LOCK DOES NOT WORK FOR LINKS Source: AIXAPAR Type: UNKNOWN IZ12119 Source: CCN Type: OSVDB ID: 40412 IBM AIX Trusted Execution trustchk_block_write Function Local Privilege Escalation Source: CCN Type: OSVDB ID: 43126 IBM AIX Hard Link File Modification Trusted Execution Failure Source: BID Type: Patch 27177 Source: CCN Type: BID-27177 IBM AIX Trusted Execution Unspecified Vulnerability Source: SECTRACK Type: UNKNOWN 1019158 Source: VUPEN Type: UNKNOWN ADV-2008-0060 Source: XF Type: UNKNOWN aix-trustchkblockwrite-security-bypass(39338) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |