HIGH
gssd in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly handle the NFSv4 Kerberos credential cache, which allows local users to bypass intended access restrictions for Kerberized NFSv4 shares via unspecified vectors
Published Oct 1, 2009
7.2
HIGHCVSS 2.0
EPSS 0.38%
Description
gssd in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly handle the NFSv4 Kerberos credential cache, which allows local users to bypass intended access restrictions for Kerberized NFSv4 shares via unspecified vectors.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (10)
- http://aix.software.ibm.com/aix/efixes/security/nfs4_advisory.asc x_refsource_CONFIRMPatchVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg1IZ49024 vendor-advisoryx_refsource_AIXAPARVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg1IZ49096 vendor-advisoryx_refsource_AIXAPARVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg1IZ49278 vendor-advisoryx_refsource_AIXAPARVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg1IZ50399 vendor-advisoryx_refsource_AIXAPARVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg1IZ50444 vendor-advisoryx_refsource_AIXAPAR
- http://www-01.ibm.com/support/docview.wss?uid=isg1IZ50496 vendor-advisoryx_refsource_AIXAPARVendor Advisory
- http://www.securityfocus.com/bid/36545 vdb-entryx_refsource_BIDPatch
- http://www.vupen.com/english/advisories/2009/2788 vdb-entryx_refsource_VUPENVendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6318 vdb-entrysignaturex_refsource_OVAL
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 1, 2009
Updated Aug 7, 2024
Reserved Oct 1, 2009
Link CVE-2009-3516
CISA Vulnrichment
Updated n/a