First published: Wed Jan 04 2012(Updated: )
The (1) bin/invscoutClient_VPD_Survey and (2) sbin/invscout_lsvpd programs in invscout.rte before 2.2.0.19 on IBM AIX 7.1, 6.1, 5.3, and earlier allow local users to delete arbitrary files, or trigger inventory scout operations on arbitrary files, via a symlink attack on an unspecified file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Invscout.rte | <=2.2.0.18 | |
Ibm Invscout.rte | =2.2.0.2 | |
Ibm Invscout.rte | =2.2.0.4 | |
Ibm Invscout.rte | =2.2.0.7 | |
Ibm Invscout.rte | =2.2.0.8 | |
Ibm Invscout.rte | =2.2.0.9 | |
Ibm Invscout.rte | =2.2.0.10 | |
Ibm Invscout.rte | =2.2.0.11 | |
Ibm Invscout.rte | =2.2.0.12 | |
Ibm Invscout.rte | =2.2.0.13 | |
Ibm Invscout.rte | =2.2.0.14 | |
Ibm Invscout.rte | =2.2.0.15 | |
Ibm Invscout.rte | =2.2.0.17 | |
IBM AIX | <=7.1 | |
IBM AIX | =5.3 | |
IBM AIX | =6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1384 is considered to be of high severity due to its ability to allow local users to delete arbitrary files.
To fix CVE-2011-1384, upgrade the invscout.rte package to version 2.2.0.19 or later.
CVE-2011-1384 affects IBM AIX versions 7.1, 6.1, 5.3, and earlier with invscout.rte versions prior to 2.2.0.19.
CVE-2011-1384 enables local users to perform a symlink attack to manipulate or delete files.
A temporary workaround for CVE-2011-1384 would be to restrict access to the affected invscout programs until they can be upgraded.