NVD
- Id
- 57856
- Name
- CVE-2007-5805
- Description
- cfgcon in IBM AIX 5.2 and 5.3 does not properly validate the argument to the "-p" option to swcons, which allows local users in the system group to create an arbitrary file, and enable world writability of this file, via a symlink attack involving use of the file"s name as the argument. NOTE: this issue is due to an incomplete fix for CVE-2007-5804.
- Reject
- CVSS Version
- 2
- CVSS Score
- 6.9
- Severity
- Medium
- CVSS Base Score
- 6.9
- CVSS Impact Subscore
- 10
- CVSS Exploit Subscore
- 3.4
- CVSS Vector
- (AV:L/AC:M/Au:N/C:C/I:C/A:C)
- Pub Date
- 2017-01-07
- Published
- 2007-11-05
- Modified Date
- 2008-09-10
- Seq
- 2007-5805