cbcvebase.
CVE-2007-5805
published 2007-11-05

CVE-2007-5805: cfgcon in IBM AIX 5.2 and 5.3 does not properly validate the argument to the "-p" option to swcons, which allows local users in the system group to create an…

PriorityP417medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.31%
22.9th percentile
cfgcon in IBM AIX 5.2 and 5.3 does not properly validate the argument to the "-p" option to swcons, which allows local users in the system group to create an arbitrary file, and enable world writability of this file, via a symlink attack involving use of the file's name as the argument. NOTE: this issue is due to an incomplete fix for CVE-2007-5804.

Affected

3 ranges
VendorProductVersion rangeFixed in
ibmaix
ibmaix
ibmaix
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.