A fix is available
APAR status
Closed as program error.
Error description
TFTP client is setuid root.
Local fix
chmod u-s /usr/bin/tftp
Problem summary
When 'nobody' user tries to put /etc/security/passwd to a local file it succeeds in loopback mode.
Problem conclusion
tftp has been fixed to set proper credentials now and also privileges in /etc/security/privcmds have been modified to prevent extra privileges.
Temporary fix
Comments
6100-06 - use AIX APAR IV40221 6100-07 - use AIX APAR IV42932 6100-08 - use AIX APAR IV42933 6100-09 - use AIX APAR IV42299 6100-09 - use AIX APAR IV42299 7100-00 - use AIX APAR IV42934 7100-01 - use AIX APAR IV42700 7100-02 - use AIX APAR IV42935
APAR Information
APAR number
IV42935
Reported component name
AIX V7.1
Reported component ID
5765H4000
Reported release
710
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Submitted date
2013-05-21
Closed date
2013-05-21
Last modified date
2013-11-24
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
AIX V7.1
Fixed component ID
5765H4000
Applicable component levels
R710 PSY U855678
UP13/07/30 I 1000
PTF to Fileset Mapping
U855678 bos.net.tcp.client 7.1.2.16
[{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SSMV87","label":"AIX 6.1 Enterprise Edition"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"710","Edition":"","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}},{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSMVAX","label":"AIX Express Edition"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"710","Edition":"","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}},{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SG11R","label":"AIX 7.1 HIPERS, APARs and Fixes"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"710","Edition":"","Line of Business":{"code":"","label":""}}]
Document Information
Modified date:
24 November 2013