{ "CVE_data_meta" : { "ASSIGNER" : "cve@mitre.org", "ID" : "CVE-2007-5805", "STATE" : "PUBLIC" }, "affects" : { "vendor" : { "vendor_data" : [ { "product" : { "product_data" : [ { "product_name" : "n/a", "version" : { "version_data" : [ { "version_value" : "n/a" } ] } } ] }, "vendor_name" : "n/a" } ] } }, "data_format" : "MITRE", "data_type" : "CVE", "data_version" : "4.0", "description" : { "description_data" : [ { "lang" : "eng", "value" : "cfgcon in IBM AIX 5.2 and 5.3 does not properly validate the argument to the \"-p\" option to swcons, which allows local users in the system group to create an arbitrary file, and enable world writability of this file, via a symlink attack involving use of the file's name as the argument. NOTE: this issue is due to an incomplete fix for CVE-2007-5804." } ] }, "problemtype" : { "problemtype_data" : [ { "description" : [ { "lang" : "eng", "value" : "n/a" } ] } ] }, "references" : { "reference_data" : [ { "name" : "20071030 IBM AIX swcons Local Arbitrary File Access Vulnerability", "refsource" : "IDEFENSE", "url" : "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=611" }, { "name" : "ftp://aix.software.ibm.com/aix/efixes/security/cfgcon_ifix.tar", "refsource" : "CONFIRM", "url" : "ftp://aix.software.ibm.com/aix/efixes/security/cfgcon_ifix.tar" }, { "name" : "http://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&heading=AIX53&path=%2F200710%2FSECURITY%2F20071030%2Fdatafile100405", "refsource" : "CONFIRM", "url" : "http://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&heading=AIX53&path=%2F200710%2FSECURITY%2F20071030%2Fdatafile100405" }, { "name" : "IZ03055", "refsource" : "AIXAPAR", "url" : "http://www-1.ibm.com/support/docview.wss?uid=isg1IZ03055" }, { "name" : "IZ03061", "refsource" : "AIXAPAR", "url" : "http://www-1.ibm.com/support/docview.wss?uid=isg1IZ03061" }, { "name" : "26258", "refsource" : "BID", "url" : "http://www.securityfocus.com/bid/26258" }, { "name" : "27437", "refsource" : "SECUNIA", "url" : "http://secunia.com/advisories/27437" }, { "name" : "aix-swcons-insecure-permissions(38154)", "refsource" : "XF", "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/38154" } ] } }