Vulnerability Name: | CVE-2008-4018 (CCN-44903) | ||||||||
Assigned: | 2008-09-03 | ||||||||
Published: | 2008-09-03 | ||||||||
Updated: | 2017-09-29 | ||||||||
Summary: | swcons in bos.rte.console in IBM AIX 5.2.0 through 6.1.1 allows local users in the system group to create or overwrite an arbitrary file, and establish weak permissions and root ownership for this file, via unspecified vectors. Note: this can be leveraged to gain privileges. Note: this issue exists because of an incomplete fix for CVE-2007-5805. | ||||||||
CVSS v3 Severity: | 7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
4.9 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CCN Type: IBM SECURITY ADVISORY, Wed Sep 3 09:53:43 CDT 2008 AIX swcons file ownership/permission vulnerability Source: CONFIRM Type: UNKNOWN http://aix.software.ibm.com/aix/efixes/security/swcons_advisory.asc Source: MITRE Type: CNA CVE-2008-4018 Source: CCN Type: SA31739 IBM AIX "swcons" Command Privilege Escalation Vulnerability Source: SECUNIA Type: UNKNOWN 31739 Source: CCN Type: SECTRACK ID: 1020818 IBM AIX swcons Bug Lets Local Users Gain Root Privileges Source: SECTRACK Type: UNKNOWN 1020818 Source: CCN Type: IBM APAR IZ18334 SYSTEM GROUP USERS CAN CREATE/MODIFY FILES REGARDLESS OF PERMS Source: CCN Type: IBM APAR IZ18335 SYSTEM GROUP USERS CAN CREATE/MODIFY FILES REGARDLESS OF PERMS Source: CCN Type: IBM APAR IZ18338 SYSTEM GROUP USERS CAN CREATE/MODIFY FILES REGARDLESS OF PERMS Source: CCN Type: IBM APAR IZ18339 SYSTEM GROUP USERS CAN CREATE/MODIFY FILES REGARDLESS OF PERMS Source: CCN Type: IBM APAR IZ18341 SYSTEM GROUP USERS CAN CREATE/MODIFY FILES REGARDLESS OF PERMS Source: AIXAPAR Type: UNKNOWN IZ18334 Source: AIXAPAR Type: UNKNOWN IZ18335 Source: AIXAPAR Type: UNKNOWN IZ18338 Source: AIXAPAR Type: UNKNOWN IZ18339 Source: AIXAPAR Type: UNKNOWN IZ18341 Source: AIXAPAR Type: UNKNOWN IZ28943 Source: CCN Type: IBM APAR IZ28943 SYSTEM GROUP USERS CAN CREATE/MODIFY FILES REGARDLESS OF PERMS Source: BID Type: UNKNOWN 30999 Source: CCN Type: BID-30999 IBM AIX 'swcons' Insecure File Creation Vulnerability Source: VUPEN Type: UNKNOWN ADV-2008-2490 Source: XF Type: UNKNOWN ibm-aix-swcons-code-execution(44903) Source: XF Type: UNKNOWN ibm-aix-swcons-code-execution(44903) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:5932 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |