First published: Sun Jun 08 2014(Updated: )
IBM SPSS Modeler 16.0 before 16.0.0.1 on UNIX does not properly drop group privileges, which allows local users to bypass intended file-access restrictions by leveraging (1) gid 0 or (2) root's group memberships.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM SPSS Modeler Subscription | =16.0.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3038 has been classified as a medium severity vulnerability.
To fix CVE-2014-3038, upgrade IBM SPSS Modeler to version 16.0.0.1 or later.
CVE-2014-3038 affects IBM SPSS Modeler 16.0 before version 16.0.0.1 on UNIX systems.
CVE-2014-3038 allows local users to bypass intended file-access restrictions due to improper group privilege handling.
CVE-2014-3038 is a local vulnerability that requires local access to exploit.