Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

AIX sadc Insecure Temporary File Creation Vulnerability

Due to insecure /tmp file creation the sadc command under some versions of AIX is vulnerable to a symlink attack. This results in normal users being able to create and/or modify files owned by group 'adm'. The /usr/lib/sa/sadc command does drop the effective group id before opening or creating the filename passed in on the command line.







 

Privacy Statement
Copyright 2009, SecurityFocus