First published: Sat Jul 06 2013(Updated: )
The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows remote authenticated users to bypass intended file-ownership restrictions, and read or overwrite arbitrary files, via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM AIX | =6.1 | |
IBM AIX | =7.1 | |
IBM Virtual I/O Server (VIOS) | =2.2.2.2-fp-26_sp-02 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3005 has been classified as a medium severity vulnerability.
To fix CVE-2013-3005, apply the latest patches provided by IBM for AIX and VIOS.
CVE-2013-3005 allows remote authenticated users to bypass file ownership restrictions, granting access to read or overwrite arbitrary files.
CVE-2013-3005 affects IBM AIX versions 6.1 and 7.1 when RBAC is enabled.
Yes, CVE-2013-3005 specifically involves a vulnerability in the TFTP client of IBM AIX and VIOS.