Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
AIX snap不安全暂时文件创建漏洞
Vulnerability Description
AIX 4.3.2之前的版本中的snap命令存在漏洞。snap命令创建带有world-readable许可的/tmp/ibmsupt目录,并且在snap -a已执行时不会移动或删除目录。本地用户可以通过在根运行snap -a之前创建/tmp/ibmsupt/general/passwd来访问隐藏密码。
CVSS Information
N/A
Vulnerability Type
N/A