6.9
CVSSv2

CVE-2014-3977

Published: 08/06/2014 Updated: 31/08/2021
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 695
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-2179.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ibm vios 2.2.1.8

ibm vios 2.2.2.4

ibm vios 2.2.1.1

ibm vios 2.2.1.3

ibm vios 2.2.3.3

ibm aix 7.1

ibm vios 2.2.3.2

ibm vios 2.2.0.10

ibm vios 2.2.1.4

ibm aix 6.1

ibm vios 2.2.0.13

ibm vios 2.2.1.0

ibm vios 2.2.2.5

ibm vios 2.2.3.0

ibm vios 2.2.0.11

ibm vios 2.2.0.12

ibm vios 2.2.1.9

ibm vios 2.2.2.0

Exploits

Vulnerability title: Privilege Escalation in IBM AIX CVE: CVE-2014-3977 Vendor: IBM Product: AIX Affected version: 618 and later Fixed version: N/A Reported by: Tim Brown Details: It has been identified that libodm allows privilege escalation via arbitrary file writes with elevated privileges (utilising SetGID and SetUID programs) The followin ...
IBM AIX versions 618 and later suffer from a local privilege escalation vulnerability in libodm due to an arbitrary file write ...