CVE-2008-1595IBM AIX vulnerability

CWE-2644 documents4 sources
Severity
4.9MEDIUMNVD
EPSS
0.0%
top 86.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 31
Latest updateMay 1

Description

The proc filesystem in the kernel in IBM AIX 5.2 and 5.3 does not properly enforce directory permissions when a file executing from a directory has weaker permissions than the directory itself, which allows local users to obtain sensitive information.

CVSS vector

AV:L/AC:L/C:C/I:N/A:NExploitability: 3.9 | Impact: 6.9

Affected Packages1 packages

NVDibm/aix5.2, 5.3, 6.1+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4jhp-q4xq-hjrq: The proc filesystem in the kernel in IBM AIX 52022-05-01
CVEList
CVE-2008-1595: The proc filesystem in the kernel in IBM AIX 52008-03-31

💥Exploits & PoCs

1
Exploit-DB
phpBB Mod Small ShoutBox 1.4 - Remote Edit/Delete Messages2008-11-05
CVE-2008-1595 — IBM AIX vulnerability | cvebase