A fix is available
APAR status
Closed as program error.
Error description
This APAR addresses a potential security issue. Any relevant information will be released via Subscription Services. Please visit https:// www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd
Local fix
Problem summary
A malicious user can do the following: ln -s /etc/<file> /tmp/syslog.out ...and when the lazy root user configures syslog to write out to the same /tmp/syslog.out file, /etc/<file> is written to
Problem conclusion
Provide a warning not to use /tmp/syslog.conf
Temporary fix
Comments
6100-06 - use AIX APAR IZ97757 7100-00 - use AIX APAR IZ96381
APAR Information
APAR number
IZ96381
Reported component name
AIX V7.1
Reported component ID
5765H4000
Reported release
710
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Submitted date
2011-03-08
Closed date
2011-03-08
Last modified date
2013-04-16
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
AIX V7.1
Fixed component ID
5765H4000
Applicable component levels
R710 PSY U833143
UP11/05/11 I 1000
PTF to Fileset Mapping
U833143 bos.net.tcp.client 7.1.0.15
[{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SSMV87","label":"AIX 6.1 Enterprise Edition"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"710","Edition":"","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}},{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSMVAX","label":"AIX Express Edition"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"710","Edition":"","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}},{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SG11R","label":"AIX 7.1 HIPERS, APARs and Fixes"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"710","Edition":"","Line of Business":{"code":"","label":""}}]
Document Information
Modified date:
16 April 2013