[原文]create_keyfiles in PSSP 3.2 with DCE 3.1 authentication on AIX creates keyfile directories with world-writable permissions, which could allow a local user to delete key files and cause a denial of service.
IBM PSSP software contains a flaw that may allow a malicious user to manipulate the keyfile directory of a PSSP node. The issue is triggered when creating keyfile directories which are created world writeable. It is possible that the flaw may allow denial of service or installation of untrusted keys resulting in a loss of integrity and/or availability.
Upgrade PSSP using the APAR numbers IY19069 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.