{"api_version":"1","generated_at":"2026-07-23T09:27:49+00:00","cve":"CVE-2007-2996","urls":{"html":"https://cve.report/CVE-2007-2996","api":"https://cve.report/api/cve/CVE-2007-2996.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-2996","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-2996"},"summary":{"title":"CVE-2007-2996","description":"Unspecified vulnerability in perl.rte 5.8.0.10 through 5.8.0.95 on IBM AIX 5.2, and 5.8.2.10 through 5.8.2.50 on AIX 5.3, allows local users to gain privileges via unspecified vectors related to the installation and \"waiting for a legitimate user to execute a binary that ships with Perl.\"","state":"PUBLISHED","assigner":"mitre","published_at":"2007-06-04 17:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.6","severity":"","vector":"AV:L/AC:M/Au:S/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:M/Au:S/C:C/I:C/A:C","baseScore":6.6,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www-1.ibm.com/support/docview.wss?uid=isg1IY98395","name":"http://www-1.ibm.com/support/docview.wss?uid=isg1IY98395","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://www-1.ibm.com/support/docview.wss?uid=isg1IY98394","name":"http://www-1.ibm.com/support/docview.wss?uid=isg1IY98394","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://www.vupen.com/english/advisories/2007/2004","name":"http://www.vupen.com/english/advisories/2007/2004","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"ftp://aix.software.ibm.com/aix/efixes/security/perl_ifix.tar.Z","name":"ftp://aix.software.ibm.com/aix/efixes/security/perl_ifix.tar.Z","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"text/plain","httpstatus":"404","archivestatus":"404"},{"url":"http://www.securityfocus.com/bid/24241","name":"http://www.securityfocus.com/bid/24241","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"IBM AIX Perl Interpreter Local Arbitrary Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www-1.ibm.com/support/search.wss?rs=0&q=IY98396&apar=only","name":"http://www-1.ibm.com/support/search.wss?rs=0&q=IY98396&apar=only","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Search results","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/25478","name":"http://secunia.com/advisories/25478","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"IBM AIX Perl Unspecified Code Execution Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/36754","name":"http://osvdb.org/36754","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securitytracker.com/id?1018177","name":"http://www.securitytracker.com/id?1018177","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Perl on IBM AIX Lets Local Users Gain Elevated Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-2996","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-2996","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"2996","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"ibm","cpe5":"aix","cpe6":"5.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2996","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"ibm","cpe5":"aix","cpe6":"5.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T13:57:54.819Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"ftp://aix.software.ibm.com/aix/efixes/security/perl_ifix.tar.Z"},{"name":"1018177","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018177"},{"name":"25478","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/25478"},{"name":"IY98394","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-1.ibm.com/support/docview.wss?uid=isg1IY98394"},{"name":"24241","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/24241"},{"name":"IY98395","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-1.ibm.com/support/docview.wss?uid=isg1IY98395"},{"name":"ADV-2007-2004","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2004"},{"name":"IY98396","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-1.ibm.com/support/search.wss?rs=0&q=IY98396&apar=only"},{"name":"36754","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/36754"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-05-22T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unspecified vulnerability in perl.rte 5.8.0.10 through 5.8.0.95 on IBM AIX 5.2, and 5.8.2.10 through 5.8.2.50 on AIX 5.3, allows local users to gain privileges via unspecified vectors related to the installation and \"waiting for a legitimate user to execute a binary that ships with Perl.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2009-02-26T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"ftp://aix.software.ibm.com/aix/efixes/security/perl_ifix.tar.Z"},{"name":"1018177","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018177"},{"name":"25478","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/25478"},{"name":"IY98394","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-1.ibm.com/support/docview.wss?uid=isg1IY98394"},{"name":"24241","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/24241"},{"name":"IY98395","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-1.ibm.com/support/docview.wss?uid=isg1IY98395"},{"name":"ADV-2007-2004","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2004"},{"name":"IY98396","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-1.ibm.com/support/search.wss?rs=0&q=IY98396&apar=only"},{"name":"36754","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/36754"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-2996","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in perl.rte 5.8.0.10 through 5.8.0.95 on IBM AIX 5.2, and 5.8.2.10 through 5.8.2.50 on AIX 5.3, allows local users to gain privileges via unspecified vectors related to the installation and \"waiting for a legitimate user to execute a binary that ships with Perl.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ftp://aix.software.ibm.com/aix/efixes/security/perl_ifix.tar.Z","refsource":"CONFIRM","url":"ftp://aix.software.ibm.com/aix/efixes/security/perl_ifix.tar.Z"},{"name":"1018177","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018177"},{"name":"25478","refsource":"SECUNIA","url":"http://secunia.com/advisories/25478"},{"name":"IY98394","refsource":"AIXAPAR","url":"http://www-1.ibm.com/support/docview.wss?uid=isg1IY98394"},{"name":"24241","refsource":"BID","url":"http://www.securityfocus.com/bid/24241"},{"name":"IY98395","refsource":"AIXAPAR","url":"http://www-1.ibm.com/support/docview.wss?uid=isg1IY98395"},{"name":"ADV-2007-2004","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2004"},{"name":"IY98396","refsource":"AIXAPAR","url":"http://www-1.ibm.com/support/search.wss?rs=0&q=IY98396&apar=only"},{"name":"36754","refsource":"OSVDB","url":"http://osvdb.org/36754"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-2996","datePublished":"2007-06-04T17:00:00.000Z","dateReserved":"2007-06-04T00:00:00.000Z","dateUpdated":"2024-08-07T13:57:54.819Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-06-04 17:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:M/Au:S/C:C/I:C/A:C","baseScore":6.6,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"MEDIUM","exploitabilityScore":2.7,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:ibm:aix:5.2:*:*:*:*:*:*:*","matchCriteriaId":"17EECCCB-D7D1-439A-9985-8FAE8B44487B"},{"vulnerable":true,"criteria":"cpe:2.3:o:ibm:aix:5.3:*:*:*:*:*:*:*","matchCriteriaId":"EA8DDF4A-1C5D-4CB1-95B3-69EAE6572507"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"2996","Ordinal":"1","Title":"CVE-2007-2996","CVE":"CVE-2007-2996","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"2996","Ordinal":"1","NoteData":"Unspecified vulnerability in perl.rte 5.8.0.10 through 5.8.0.95 on IBM AIX 5.2, and 5.8.2.10 through 5.8.2.50 on AIX 5.3, allows local users to gain privileges via unspecified vectors related to the installation and \"waiting for a legitimate user to execute a binary that ships with Perl.\"","Type":"Description","Title":"CVE-2007-2996"},{"CveYear":"2007","CveId":"2996","Ordinal":"2","NoteData":"2007-06-04","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"2996","Ordinal":"3","NoteData":"2009-02-26","Type":"Other","Title":"Modified"}]}}}