CVE-2007-5804
Last modified
CVE-2007-5804 is a vulnerability of currently unknown severity. cfgcon in IBM AIX 5.2 and 5.3 does not properly validate the argument to the "-p" option to swcons, which allows local users in the system group to create or overwrite an arbitrary file, and enable world writability of this file, by using the file's name as the argument.. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
cfgcon in IBM AIX 5.2 and 5.3 does not properly validate the argument to the "-p" option to swcons, which allows local users in the system group to create or overwrite an arbitrary file, and enable world writability of this file, by using the file's name as the argument.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Aix | 5.2 |
| Ibm | Aix | 5.3 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-5804?
How severe is CVE-2007-5804?
How do I fix CVE-2007-5804?
Are you affected by CVE-2007-5804?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
