CVE-2008-4018
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
swcons in bos.rte.console in IBM AIX 5.2.0 through 6.1.1 allows local users in the system group to create or overwrite an arbitrary file, and establish weak permissions and root ownership for this file, via unspecified vectors. NOTE: this can be leveraged to gain privileges. NOTE: this issue exists because of an incomplete fix for CVE-2007-5805.
swcons en bos.rte.console en IBM AIX v5.2.0 a v 6.1.1, permite a usuarios locales en el grupo de "sistema" crear o sobreescribir archivos de su elección y establecer permisos débiles y asignar la propiedad del archivo a administradores a través de vectores no especificados. NOTA: esto puede ser aprovechado para obtener privielegios. NOTA: esta vulnerabilidad existe por un fallo no corregido en CVE-2007-5805.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-09-10 CVE Reserved
- 2008-09-10 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
http://aix.software.ibm.com/aix/efixes/security/swcons_advisory.asc | X_refsource_confirm | |
http://secunia.com/advisories/31739 | Third Party Advisory | |
http://securitytracker.com/id?1020818 | Vdb Entry | |
http://www.securityfocus.com/bid/30999 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/2490 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/44903 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5932 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.ibm.com/support/docview.wss?uid=isg1IZ18334 | 2017-09-29 | |
http://www.ibm.com/support/docview.wss?uid=isg1IZ18335 | 2017-09-29 | |
http://www.ibm.com/support/docview.wss?uid=isg1IZ18338 | 2017-09-29 | |
http://www.ibm.com/support/docview.wss?uid=isg1IZ18339 | 2017-09-29 | |
http://www.ibm.com/support/docview.wss?uid=isg1IZ18341 | 2017-09-29 | |
http://www.ibm.com/support/docview.wss?uid=isg1IZ28943 | 2017-09-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Aix Search vendor "Ibm" for product "Aix" | 5.2 Search vendor "Ibm" for product "Aix" and version "5.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Aix Search vendor "Ibm" for product "Aix" | 5.3 Search vendor "Ibm" for product "Aix" and version "5.3" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Aix Search vendor "Ibm" for product "Aix" | 6.1 Search vendor "Ibm" for product "Aix" and version "6.1" | - |
Affected
|