CVE-2014-3977

medium
Published 2014-06-08 · Modified 2026-05-06
CVSS v3
CVSS v2
6.9
VIR risk
6.9

Description

libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-2179.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Application impact

VendorProductVersionsFixed
ibmvios2.2.0.10
ibmvios2.2.0.11
ibmvios2.2.0.12
ibmvios2.2.0.13
ibmvios2.2.1.0
ibmvios2.2.1.1
ibmvios2.2.1.3
ibmvios2.2.1.4
ibmvios2.2.1.8
ibmvios2.2.1.9
ibmvios2.2.2.0
ibmvios2.2.2.4
ibmvios2.2.2.5
ibmvios2.2.3.0
ibmvios2.2.3.2
ibmvios2.2.3.3

References

CWEs

CWE-59

Verify integrity in audit chain (admin only). AS-IS.