IBM ctstrtcasd file overwrite

ctstrtcasd-file-overwrite (17514) The risk level is classified as LowLow Risk

Description:

ctstrtcasd could allow a local attacker to corrupt arbitrary files on the system. A local attacker could specify the -f option and insert 65,636 bytes of application trace data to overwrite existing files on the system with root privileges or to create non-existent files. A local attacker could exploit this vulnerability to cause a denial of service by causing damage to the system or by consuming all available hard disk space.


Consequences:

Denial of Service

Remedy:

For IBM AIX 5.2:
No remedy available as of September 2004.

For IBM AIX 5.3:
Apply APAR IY61770 patch, available from the IBM Technical Support Web site. See References.

For Tivoli System Automation for Linux 1.1:
Apply the work around as listed in IBM Managed Security Services Outside Advisory Redistribution MSS-OAR-E01-2004:1480.1. See References.

For IBM Tivoli System Automation for Multiplatforms 1.2:
Apply the work around as listed in IBM Managed Security Services Outside Advisory Redistribution MSS-OAR-E01-2004:1480.1. See References.

For CSM PTF 1.4.0.3:
No remedy available as of September 2004.

For HMC PTF U800398 for HMC Version Release 3.0, 3.1, and 3.2:
No remedy available as of September 2004.

For HMC PTF MH00148 for HMC Version 4 Release 1.0 and 2.0:
No remedy available as of September 2004.

For General Parallel File System (GPFS):
No remedy available as of September 2004.

References:

  • BugTraq Mailing List, Mon Sep 27 2004 - 15:28:38 CDT T: iDEFENSE Security Advisory 09.27.04 - IBM AIX ctstrtcasd Local File Corruption Vulnerability.
  • IBM AIX APAR IY61770: IY61770: MISC SERVICE UPDATES.
  • BID-11264: IBM CTSTRTCASD Utility Local File Corruption Vulnerability
  • CVE-2004-0828: The ctstrtcasd program in RSCT 2.3.0.0 and earlier on IBM AIX 5.2 and 5.3 does not properly drop privileges before executing the -f option, which allows local users to modify or create arbitrary files.
  • SA12664: IBM Products ctstrtcasd Local File Corruption Vulnerability
  • SECTRACK ID: 1011429: IBM Reliable Scalable Cluster Technology (RSCT) Lets Local Users Corrupt Files

Platforms Affected:

  • IBM AIX 5.2
  • IBM AIX 5.3

Reported:

Sep 27, 2004

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page