{"api_version":"1","generated_at":"2026-07-23T11:57:40+00:00","cve":"CVE-2007-4353","urls":{"html":"https://cve.report/CVE-2007-4353","api":"https://cve.report/api/cve/CVE-2007-4353.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-4353","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-4353"},"summary":{"title":"CVE-2007-4353","description":"Multiple buffer overflows in IBM AIX 5.2 and 5.3 allow local users in the system group to gain root privileges via unspecified vectors involving the (1) chpath, (2) rmpath, and (3) devinstall programs in bos.rte.methods.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-08-15 00:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.9","severity":"","vector":"AV:L/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:C/I:C/A:C","baseScore":6.9,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2007/2860","name":"http://www.vupen.com/english/advisories/2007/2860","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-1.ibm.com/support/docview.wss?uid=isg1IZ00531","name":"http://www-1.ibm.com/support/docview.wss?uid=isg1IZ00531","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://secunia.com/advisories/26420","name":"http://secunia.com/advisories/26420","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"IBM AIX Multiple Privilege Escalation Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/25270","name":"http://www.securityfocus.com/bid/25270","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM AIX Configuration Commands Multiple Buffer Overflow Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"ftp://aix.software.ibm.com/aix/efixes/security/README","name":"ftp://aix.software.ibm.com/aix/efixes/security/README","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"404"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35971","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35971","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-1.ibm.com/support/docview.wss?uid=isg1IZ01433","name":"http://www-1.ibm.com/support/docview.wss?uid=isg1IZ01433","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://www.securitytracker.com/id?1018549","name":"http://www.securitytracker.com/id?1018549","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM AIX Buffer Overflows in chpath, rmpath, and devinstall Commands Let Local Users Gain Root Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-4353","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-4353","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"4353","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"ibm","cpe5":"aix","cpe6":"5.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"4353","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"ibm","cpe5":"aix","cpe6":"5.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T14:53:55.784Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2007-2860","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2860"},{"name":"IZ00531","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-1.ibm.com/support/docview.wss?uid=isg1IZ00531"},{"name":"aix-chpath-rmpath-devinstall-bo(35971)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35971"},{"name":"IZ01433","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-1.ibm.com/support/docview.wss?uid=isg1IZ01433"},{"name":"1018549","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018549"},{"name":"26420","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26420"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"ftp://aix.software.ibm.com/aix/efixes/security/README"},{"name":"25270","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/25270"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-08-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple buffer overflows in IBM AIX 5.2 and 5.3 allow local users in the system group to gain root privileges via unspecified vectors involving the (1) chpath, (2) rmpath, and (3) devinstall programs in bos.rte.methods."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2007-2860","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2860"},{"name":"IZ00531","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-1.ibm.com/support/docview.wss?uid=isg1IZ00531"},{"name":"aix-chpath-rmpath-devinstall-bo(35971)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35971"},{"name":"IZ01433","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-1.ibm.com/support/docview.wss?uid=isg1IZ01433"},{"name":"1018549","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018549"},{"name":"26420","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26420"},{"tags":["x_refsource_CONFIRM"],"url":"ftp://aix.software.ibm.com/aix/efixes/security/README"},{"name":"25270","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/25270"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-4353","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple buffer overflows in IBM AIX 5.2 and 5.3 allow local users in the system group to gain root privileges via unspecified vectors involving the (1) chpath, (2) rmpath, and (3) devinstall programs in bos.rte.methods."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2007-2860","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2860"},{"name":"IZ00531","refsource":"AIXAPAR","url":"http://www-1.ibm.com/support/docview.wss?uid=isg1IZ00531"},{"name":"aix-chpath-rmpath-devinstall-bo(35971)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35971"},{"name":"IZ01433","refsource":"AIXAPAR","url":"http://www-1.ibm.com/support/docview.wss?uid=isg1IZ01433"},{"name":"1018549","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018549"},{"name":"26420","refsource":"SECUNIA","url":"http://secunia.com/advisories/26420"},{"name":"ftp://aix.software.ibm.com/aix/efixes/security/README","refsource":"CONFIRM","url":"ftp://aix.software.ibm.com/aix/efixes/security/README"},{"name":"25270","refsource":"BID","url":"http://www.securityfocus.com/bid/25270"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-4353","datePublished":"2007-08-15T00:00:00.000Z","dateReserved":"2007-08-14T00:00:00.000Z","dateUpdated":"2024-08-07T14:53:55.784Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-08-15 00:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:C/I:C/A:C","baseScore":6.9,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"MEDIUM","exploitabilityScore":3.4,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:ibm:aix:5.2:*:*:*:*:*:*:*","matchCriteriaId":"17EECCCB-D7D1-439A-9985-8FAE8B44487B"},{"vulnerable":true,"criteria":"cpe:2.3:o:ibm:aix:5.3:*:*:*:*:*:*:*","matchCriteriaId":"EA8DDF4A-1C5D-4CB1-95B3-69EAE6572507"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"4353","Ordinal":"1","Title":"CVE-2007-4353","CVE":"CVE-2007-4353","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"4353","Ordinal":"1","NoteData":"Multiple buffer overflows in IBM AIX 5.2 and 5.3 allow local users in the system group to gain root privileges via unspecified vectors involving the (1) chpath, (2) rmpath, and (3) devinstall programs in bos.rte.methods.","Type":"Description","Title":"CVE-2007-4353"},{"CveYear":"2007","CveId":"4353","Ordinal":"2","NoteData":"2007-08-14","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"4353","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}