First published: Thu Feb 10 2005(Updated: )
lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing the -f option, which allows local users to read one line of arbitrary files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM AIX | =5.3 | |
IBM AIX | =5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0261 is considered a moderate severity vulnerability due to its potential for local users to read arbitrary files.
To fix CVE-2005-0261, it is recommended to apply the relevant patches provided by IBM for AIX versions 5.2 and 5.3.
CVE-2005-0261 affects IBM AIX versions 5.2 and 5.3, and potentially earlier releases.
CVE-2005-0261 allows local users to read the contents of arbitrary files due to insufficient privilege management.
No, CVE-2005-0261 is a local vulnerability and requires access to the affected system to exploit.