Description
sadc in IBM AIX 4.1 through 4.3, when called from programs such as timex that are setgid adm, allows local users to overwrite arbitrary files via a symlink attack.
References (6)
Core 6
Core References
Various Sources x_refsource_confirm
http://techsupport.services.ibm.com/aix/fixes/v4/os/bos.acct.4.3.1.0.info
Various Sources vendor-advisory
x_refsource_aixapar
http://www-1.ibm.com/support/search.wss?rs=0&q=IX75554&apar=only
Various Sources vendor-advisory
x_refsource_aixapar
http://www-1.ibm.com/support/search.wss?rs=0&q=IX76330&apar=only
Patch, Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/408
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/7675
Various Sources vendor-advisory
x_refsource_aixapar
http://www-1.ibm.com/support/search.wss?rs=0&q=IX76853&apar=only
Scores
EPSS
0.0031
EPSS Percentile
22.9%
Details
Status
published
Products (9)
ibm/aix
4.1
ibm/aix
4.1.1
ibm/aix
4.1.2
ibm/aix
4.1.3
ibm/aix
4.1.4
ibm/aix
4.1.5
ibm/aix
4.2
ibm/aix
4.2.1
ibm/aix
4.3
Published
Feb 25, 1998
Tracked Since
Feb 18, 2026