First published: Sun Jun 08 2014(Updated: )
libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-2179.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Virtual I/O Server (VIOS) | =2.2.0.10 | |
IBM Virtual I/O Server (VIOS) | =2.2.0.11 | |
IBM Virtual I/O Server (VIOS) | =2.2.0.12 | |
IBM Virtual I/O Server (VIOS) | =2.2.0.13 | |
IBM Virtual I/O Server (VIOS) | =2.2.1.0 | |
IBM Virtual I/O Server (VIOS) | =2.2.1.1 | |
IBM Virtual I/O Server (VIOS) | =2.2.1.3 | |
IBM Virtual I/O Server (VIOS) | =2.2.1.4 | |
IBM Virtual I/O Server (VIOS) | =2.2.1.4-fp-25_sp-02 | |
IBM Virtual I/O Server (VIOS) | =2.2.1.8 | |
IBM Virtual I/O Server (VIOS) | =2.2.1.9 | |
IBM Virtual I/O Server (VIOS) | =2.2.2.0 | |
IBM Virtual I/O Server (VIOS) | =2.2.2.4 | |
IBM Virtual I/O Server (VIOS) | =2.2.2.5 | |
IBM Virtual I/O Server (VIOS) | =2.2.3.0 | |
IBM Virtual I/O Server (VIOS) | =2.2.3.2 | |
IBM Virtual I/O Server (VIOS) | =2.2.3.3 | |
IBM AIX | =6.1 | |
IBM AIX | =7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3977 is rated as a moderate severity vulnerability due to its potential for local privilege escalation via a symlink attack.
To fix CVE-2014-3977, ensure that your IBM AIX or VIOS installation is updated to the latest version provided by IBM addressing this vulnerability.
CVE-2014-3977 affects IBM AIX 6.1, AIX 7.1, and various versions of IBM VIOS.
CVE-2014-3977 involves a symlink attack that allows local users to overwrite arbitrary files.
Yes, CVE-2014-3977 is related to an incomplete fix for CVE-2012-2179.