include/tests_webservers in Lynis before 1.5.5 on AIX allows local users to overwrite arbitrary files via a symlink attack on a /tmp/lynis.##### file.
| Software | From | Fixed in |
|---|---|---|
| cisofy / lynis | - | 1.5.4.x |
| cisofy / lynis | 1.5.3 | 1.5.3.x |
| cisofy / lynis | 1.5.2 | 1.5.2.x |
| cisofy / lynis | 1.5.0 | 1.5.0.x |
| cisofy / lynis | 1.5.1 | 1.5.1.x |