First published: Tue May 25 1999(Updated: )
The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM AIX eNetwork Firewall | =3.2 | |
IBM AIX eNetwork Firewall | =3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0803 has been classified as a medium severity vulnerability due to its potential for local users to exploit it via symlink attacks.
To fix CVE-1999-0803, users should restrict file permissions and ensure that the fwluser script does not allow unprivileged users to create symlinks.
CVE-1999-0803 affects IBM AIX eNetwork Firewall versions 3.2 and 3.3.
The impact of CVE-1999-0803 allows local users to overwrite arbitrary files, potentially leading to unauthorized access or data loss.
A potential workaround for CVE-1999-0803 is to limit the execution of the fwluser script to trusted users only.