CVE-2009-3516
IBM AIX 5.3.x-5.3.9 and 6.1.0-6.1.2 - Unauthenticated Access Restriction Bypass via NFSv4 Kerberos Credential Cache
Title source: llmDescription
gssd in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly handle the NFSv4 Kerberos credential cache, which allows local users to bypass intended access restrictions for Kerberized NFSv4 shares via unspecified vectors.
References (10)
Core 10
Core References
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/2788
Vendor Advisory vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=isg1IZ50496
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=isg1IZ50444
Vendor Advisory vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=isg1IZ50399
Vendor Advisory vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=isg1IZ49278
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6318
Vendor Advisory vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=isg1IZ49096
Vendor Advisory vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=isg1IZ49024
Patch vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/36545
Patch, Vendor Advisory x_refsource_confirm
http://aix.software.ibm.com/aix/efixes/security/nfs4_advisory.asc
Scores
EPSS
0.0037
EPSS Percentile
30.1%
Details
CWE
CWE-255
Status
published
Products (7)
ibm/aix
5.3.0
ibm/aix
5.3.7
ibm/aix
5.3.8
ibm/aix
6.1
ibm/aix
6.1.0
ibm/aix
6.1.1
ibm/aix
6.1.2
Published
Oct 01, 2009
Tracked Since
Feb 18, 2026