snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.
1999-02-17T05:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | ibm | aix | 3.2.5 | Yes |
Operating System | ibm | aix | 4.1 | Yes |
Operating System | ibm | aix | 4.1.2 | Yes |
Operating System | ibm | aix | 4.1.3 | Yes |
Operating System | ibm | aix | 4.1.4 | Yes |
Operating System | ibm | aix | 4.1.5 | Yes |
Operating System | ibm | aix | 4.2 | Yes |
Operating System | ibm | aix | 4.2.1 | Yes |