libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-2179.
Recent assessments:
timb-machine at March 05, 2021 12:41am UTC reported:
<https://www.portcullis.co.uk/security-research-and-downloads/security-advisories/cve-2014-3977/>
Assessed Attacker Value: 5
Assessed Attacker Value: 5Assessed Attacker Value: 5
aix.software.ibm.com/aix/efixes/security/libodm_advisory.asc
packetstormsecurity.com/files/127067/IBM-AIX-6.1.8-Privilege-Escalation.html
www.exploit-db.com/exploits/33725
www.ibm.com/support/docview.wss?uid=isg1IV60299
www.ibm.com/support/docview.wss?uid=isg1IV60303
www.ibm.com/support/docview.wss?uid=isg1IV60311
www.ibm.com/support/docview.wss?uid=isg1IV60312
www.ibm.com/support/docview.wss?uid=isg1IV60313
www.ibm.com/support/docview.wss?uid=isg1IV60314
www.securitytracker.com/id/1030401
cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3977
exchange.xforce.ibmcloud.com/vulnerabilities/93595
www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-3977