CVE-2004-2634: Medium severity IBM AIX vulnerability
Published Dec 31, 2004
·Updated
The (1) bos.rte.servaid or (2) bos.rte.console filesets in IBM AIX 5.1 and 5.2 allow local users to overwrite arbitrary files via a symlink attack on temporary files via unknown attack vectors.
Affected Software
4 affected components
IBM AIX=5.2
IBM AIX=5.1
IBM AIX=5.1
IBM AIX=5.2
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Dec 5, 2005
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2634?
CVE-2004-2634 is classified as a local privilege escalation vulnerability.
2
How do I fix CVE-2004-2634?
To mitigate CVE-2004-2634, ensure that the affected IBM AIX filesets are updated with available security patches.
3
What are the affected versions for CVE-2004-2634?
CVE-2004-2634 affects IBM AIX versions 5.1 and 5.2.
4
Can CVE-2004-2634 be exploited remotely?
No, CVE-2004-2634 requires local access to exploit the symlink vulnerability.
5
Who can be affected by CVE-2004-2634?
Local users on systems running AIX 5.1 or 5.2 can be affected by CVE-2004-2634.