CVE-2011-1384 Information

Description

The (1) bin/invscoutClient_VPD_Survey and (2) sbin/invscout_lsvpd programs in invscout.rte before 2.2.0.19 on IBM AIX 7.1 6.1 5.3 and earlier allow local users to delete arbitrary files or trigger inventory scout operations on arbitrary files via a symlink attack on an unspecified file.

Reference

http://aix.software.ibm.com/aix/efixes/security/invscout_advisory2.asc http://secunia.com/advisories/47222 http://www.securityfocus.com/bid/51059 http://www.securityfocus.com/bid/51083 http://www-01.ibm.com/support/docview.wss?uid=isg1IV11643 https://exchange.xforce.ibmcloud.com/vulnerabilities/71615

Share on: