IBM AIX ftpd "quote cwd" Full Path Disclosure Weakness
Report ID:
SA30360
Source:
Secunia
Date of Discovery:
22.05.2008
Criticality:
Negligible
Affects:
AIX 5.x
AIX 6.x
Compromise From:
From remote
Compromise Type:
Exposure of system information
Summary
A weakness has been reported in IBM AIX, which can be exploited by malicious people to disclose system information.
Detailed Description
A weakness has been reported in IBM AIX, which can be exploited by malicious people to disclose system information.
The problem is that it is possible to disclose the full path of the home directory of the anonymous ftp user via a "quote cwd" command on an ftpd server with anonymous login enabled.
The weakness is reported in versions 5.2, 5.3, and 6.1.