CVE-2014-3977: Medium severity IBM VIOS vulnerability
Published Jun 8, 2014
·Updated
libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-2179.
Affected Software
19 affected components
IBM VIOS=2.2.0.10
IBM VIOS=2.2.0.11
IBM VIOS=2.2.0.12
IBM VIOS=2.2.0.13
IBM VIOS=2.2.1.0
IBM VIOS=2.2.1.1
IBM VIOS=2.2.1.3
IBM VIOS=2.2.1.4
IBM VIOS=2.2.1.4-fp-25_sp-02
IBM VIOS=2.2.1.8
IBM VIOS=2.2.1.9
IBM VIOS=2.2.2.0
IBM VIOS=2.2.2.4
IBM VIOS=2.2.2.5
IBM VIOS=2.2.3.0
IBM VIOS=2.2.3.2
IBM VIOS=2.2.3.3
IBM AIX=6.1
IBM AIX=7.1
Event History
Jun 8, 2014
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
via NVD·11:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-3977?
CVE-2014-3977 is rated as a moderate severity vulnerability due to its potential for local privilege escalation via a symlink attack.
2
How do I fix CVE-2014-3977?
To fix CVE-2014-3977, ensure that your IBM AIX or VIOS installation is updated to the latest version provided by IBM addressing this vulnerability.
3
What systems are affected by CVE-2014-3977?
CVE-2014-3977 affects IBM AIX 6.1, AIX 7.1, and various versions of IBM VIOS.
4
What type of attack does CVE-2014-3977 involve?
CVE-2014-3977 involves a symlink attack that allows local users to overwrite arbitrary files.
5
Is CVE-2014-3977 related to any other vulnerabilities?
Yes, CVE-2014-3977 is related to an incomplete fix for CVE-2012-2179.