MEDIUM · 4.0

CVE-2011-1384

The (1) bin/invscoutClient_VPD_Survey and (2) sbin/invscout_lsvpd programs in invscout.rte before 2.2.0.19 on IBM AIX 7.1, 6.1, 5.3, and earlier allow local users to delete arbitrary files, or trigger...

Vulnerability Description

The (1) bin/invscoutClient_VPD_Survey and (2) sbin/invscout_lsvpd programs in invscout.rte before 2.2.0.19 on IBM AIX 7.1, 6.1, 5.3, and earlier allow local users to delete arbitrary files, or trigger inventory scout operations on arbitrary files, via a symlink attack on an unspecified file.

CVSS Score

4.0

MEDIUM

AV:L/AC:H/Au:N/C:N/I:C/A:N
Confidentiality
NONE
Integrity
COMPLETE
Availability
NONE

Affected Products

VendorProductVersions
IbmInvscout.Rte<= 2.2.0.18
IbmAix<= 7.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-1384?

CVE-2011-1384 is a vulnerability with a CVSS score of 4.0 (MEDIUM). The (1) bin/invscoutClient_VPD_Survey and (2) sbin/invscout_lsvpd programs in invscout.rte before 2.2.0.19 on IBM AIX 7.1, 6.1, 5.3, and earlier allow local users to delete arbitrary files, or trigger...

How severe is CVE-2011-1384?

CVE-2011-1384 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-1384?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Invscout.Rte, Ibm Aix.