First published: Mon Jan 10 2000(Updated: )
AIX techlibss allows local users to overwrite files via a symlink attack.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM AIX | =4.3.2 | |
=4.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0080 is classified as a medium severity vulnerability due to its potential for local file overwrite by users.
To fix CVE-2000-0080, ensure that proper permissions and access controls are set on sensitive files to prevent unauthorized symlink creation.
CVE-2000-0080 affects users running IBM AIX version 4.3.2.
A symlink attack in CVE-2000-0080 occurs when a local user creates a symbolic link to overwrite a file that they should not have permission to modify.
A potential workaround for CVE-2000-0080 is to regularly monitor file permissions and restrict access to sensitive directories.