CVE-2014-3038 Information

Description

IBM SPSS Modeler 16.0 before 16.0.0.1 on UNIX does not properly drop group privileges which allows local users to bypass intended file-access restrictions by leveraging (1) gid 0 or (2) root’s group memberships.

Reference

http://secunia.com/advisories/59244 http://www.securityfocus.com/bid/67949 http://www-01.ibm.com/support/docview.wss?uid=swg21675043 https://exchange.xforce.ibmcloud.com/vulnerabilities/93304

Share on: