AIX dpid2 Core Dump Insecure Temporary File Creation Vulnerability

When dpid2 under some versions of AIX core dumps, the core file is left in /var/tmp which is world-writable. This allows malicious users to leverage a symlink attack against dpid2 and overwrite any file on the system.


 

Privacy Statement
Copyright 2010, SecurityFocus