10
CVSSv2

CVE-1999-1405

Published: 17/02/1999 Updated: 18/10/2016
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

snap command in AIX prior to 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm aix 4.2

ibm aix 4.2.1

ibm aix 4.1.4

ibm aix 4.1.5

ibm aix 3.2.5

ibm aix 4.1

ibm aix 4.1.2

ibm aix 4.1.3

Exploits

source: wwwsecurityfocuscom/bid/375/info The snap command is a diagnostic utlitiy for gathering system information on AIX platforms It can only be executed by root, but it copies various system files into /tmp/ibmsupt/ under /tmp/ibmsupt/general/ you will find the passwd file with cyphertext The danger here is if a system administrator ...