Junglewise Threat Intelligence

CVE-1999-1486: IBM AIX arbitrary file overwrite in sadc via symlink attack

CVE-1999-1486 · Severity: low · CVSS 1.2 · Published 1998-02-25

Technologies: IBM Aix. Vendors: IBM.

Executive brief

A vulnerability in the IBM AIX operating system could allow a local user to corrupt or overwrite system files. This occurs through a component used for system activity data collection when it is triggered by certain administrative utilities. An attacker could use this flaw to disrupt system operations or damage critical data, though it requires specific conditions to exploit.

Technical details

The 'sadc' (System Activity Data Collector) utility in IBM AIX 4.1, 4.2, and 4.3 is vulnerable to a symlink attack. When 'sadc' is invoked by programs with 'setgid adm' privileges, such as 'timex', it does not securely handle file creation or writes. A local attacker can create a symbolic link from a temporary file location to a target system file, causing 'sadc' to overwrite the target file with its output. This is a local privilege escalation/file integrity issue requiring local access and specific timing or configuration conditions.

Affected products

  • IBM AIX 4.1 through 4.3

Timeline

  • 1998-02-25: disclosed

References

Related threats