CVE-2004-2634
Description
Local users can overwrite arbitrary files via symlink attacks on temporary files in AIX 5.1 and 5.2 bos.rte.serv_aid and bos.rte.console filesets.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Local users can overwrite arbitrary files via symlink attacks on temporary files in AIX 5.1 and 5.2 bos.rte.serv_aid and bos.rte.console filesets.
Vulnerability
The vulnerability exists in the bos.rte.serv_aid and bos.rte.console filesets in IBM AIX versions 5.1 and 5.2. These filesets create temporary files in an insecure manner, allowing a local user to perform a symlink attack to overwrite arbitrary files on the system. The exact attack vectors are not fully disclosed in the available references [1].
Exploitation
An attacker must have local access to the system and be able to create symbolic links. The attacker can predict or control the temporary file names used by the vulnerable filesets. By placing a symlink pointing to a target file (e.g., a system configuration file) in the location where the temporary file is created, the attacker can cause the fileset to write to the target file instead. No authentication beyond local user credentials is required.
Impact
Successful exploitation allows a local attacker to overwrite arbitrary files on the system, potentially leading to privilege escalation, denial of service, or system compromise. The attacker gains the ability to modify critical system files, which can result in full control over the affected AIX system.
Mitigation
IBM released fixes for this issue via APARs IY55790 and IY55789, but the specific fixed versions are not detailed in the available references [1]. Administrators should apply the latest AIX maintenance packages or contact IBM support for the appropriate patches. As a workaround, ensure that temporary directories are not world-writable and monitor for suspicious symlink creation.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- secunia.com/advisories/11496nvdPatchVendor Advisory
- securitytracker.com/idnvdPatch
- www.osvdb.org/5711nvdPatch
- www.osvdb.org/5712nvdPatch
- www.securityfocus.com/bid/10231nvdPatch
- techsupport.services.ibm.com/server/pseries.subscriptionSvcsnvdPatch
- www-1.ibm.com/support/search.wssnvd
- www-1.ibm.com/support/search.wssnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/16008nvd
News mentions
0No linked articles in our index yet.