CVE-2001-1079IBM AIX vulnerability

3 documents3 sources
Severity
3.6LOWNVD
EPSS
0.0%
top 86.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 13
Latest updateApr 30

Description

create_keyfiles in PSSP 3.2 with DCE 3.1 authentication on AIX creates keyfile directories with world-writable permissions, which could allow a local user to delete key files and cause a denial of service.

CVSS vector

AV:L/AC:L/C:N/I:P/A:PExploitability: 3.9 | Impact: 4.9

Affected Packages1 packages

NVDibm/aix3.2.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-v5fc-vg2r-5f25: create_keyfiles in PSSP 32022-04-30
CVEList
CVE-2001-1079: create_keyfiles in PSSP 32002-06-25
CVE-2001-1079 — IBM AIX vulnerability | cvebase