CVE-2013-3005: High severity IBM AIX vulnerability
Published Jul 6, 2013
·Updated
The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows remote authenticated users to bypass intended file-ownership restrictions, and read or overwrite arbitrary files, via unspecified vectors.
Affected Software
3 affected components
IBM AIX=6.1
IBM AIX=7.1
IBM VIOS=2.2.2.2-fp-26_sp-02
Event History
Jul 6, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-3005?
CVE-2013-3005 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2013-3005?
To fix CVE-2013-3005, apply the latest patches provided by IBM for AIX and VIOS.
3
What does CVE-2013-3005 allow authenticated users to do?
CVE-2013-3005 allows remote authenticated users to bypass file ownership restrictions, granting access to read or overwrite arbitrary files.
4
Which versions of AIX are affected by CVE-2013-3005?
CVE-2013-3005 affects IBM AIX versions 6.1 and 7.1 when RBAC is enabled.
5
Is CVE-2013-3005 related to TFTP?
Yes, CVE-2013-3005 specifically involves a vulnerability in the TFTP client of IBM AIX and VIOS.