CVE-2007-5804

N/A Unknown
Published: November 05, 2007 Modified: April 23, 2026
View on NVD

Description

cfgcon in IBM AIX 5.2 and 5.3 does not properly validate the argument to the "-p" option to swcons, which allows local users in the system group to create or overwrite an arbitrary file, and enable world writability of this file, by using the file's name as the argument.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://www.securityfocus.com/bid/26258
Source: cve@mitre.org
Patch
ftp://aix.software.ibm.com/aix/efixes/security/cfgcon_ifix.tar
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
http://secunia.com/advisories/27437
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-1.ibm.com/support/docview.wss?uid=isg1IZ03055
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-1.ibm.com/support/docview.wss?uid=isg1IZ03061
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/26258
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/38154
Source: af854a3a-2127-422b-91ae-364da2661108

16 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
0.3%
22th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

ibm