First published: Mon Mar 31 2008(Updated: )
The proc filesystem in the kernel in IBM AIX 5.2 and 5.3 does not properly enforce directory permissions when a file executing from a directory has weaker permissions than the directory itself, which allows local users to obtain sensitive information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM AIX | =5.3 | |
IBM AIX | =5.2 | |
IBM AIX | =6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1595 is considered a high severity vulnerability due to its potential for compromising sensitive information.
To mitigate CVE-2008-1595, ensure proper directory and file permission settings are enforced on the affected systems.
CVE-2008-1595 affects IBM AIX versions 5.2, 5.3, and potentially 6.1 based on kernel configurations.
CVE-2008-1595 is a local privilege escalation vulnerability within the proc filesystem of the IBM AIX operating system.
No, CVE-2008-1595 requires local access for exploitation, making it a local security vulnerability.