First published: Tue May 26 2009(Updated: )
The malloc subsystem in libc in IBM AIX 5.3 and 6.1 allows local users to create or overwrite arbitrary files via a symlink attack on the log file associated with the MALLOCDEBUG environment variable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM AIX | =5.3 | |
IBM AIX | =6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1786 is considered a moderate severity vulnerability due to its potential for local exploitation.
To fix CVE-2009-1786, update your IBM AIX to the latest version that addresses the vulnerability.
CVE-2009-1786 affects local users on IBM AIX versions 5.3 and 6.1.
CVE-2009-1786 is associated with a symlink attack that allows file creation or overwriting.
The malloc subsystem in libc is the vulnerable component in CVE-2009-1786.