IBM AIX CHCOD Local Privilege Escalation Vulnerability
BID:12060
Info
IBM AIX CHCOD Local Privilege Escalation Vulnerability
| Bugtraq ID: | 12060 |
| Class: | Unknown |
| CVE: |
CVE-2004-1028 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 21 2004 12:00AM |
| Updated: | Jul 12 2009 09:26AM |
| Credit: | Discovery of this vulnerability is credited to iDEFENSE Labs. |
| Vulnerable: |
IBM AIX 5.3 L IBM AIX 5.2.2 IBM AIX 5.2 L IBM AIX 5.1 L IBM AIX 5.3 IBM AIX 5.2 IBM AIX 5.1 |
| Not Vulnerable: | |
Discussion
IBM AIX CHCOD Local Privilege Escalation Vulnerability
The AIX 'chcod' utility is reported prone to a local privilege escalation vulnerability. The vendor describes that this vulnerability results from an insecure path handling issue.
Reports indicate that this issue may be exploited by a local user that is a member of the 'system' group to run arbitrary code as the superuser.
The AIX 'chcod' utility is reported prone to a local privilege escalation vulnerability. The vendor describes that this vulnerability results from an insecure path handling issue.
Reports indicate that this issue may be exploited by a local user that is a member of the 'system' group to run arbitrary code as the superuser.
Exploit / POC
IBM AIX CHCOD Local Privilege Escalation Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
IBM AIX CHCOD Local Privilege Escalation Vulnerability
Solution:
The vendor has released an advisory and APARs to address this vulnerability, please see the referenced advisory for further detail in regards to obtaining and installing appropriate APARs.
IBM AIX 5.1
IBM AIX 5.2
IBM AIX 5.3
Solution:
The vendor has released an advisory and APARs to address this vulnerability, please see the referenced advisory for further detail in regards to obtaining and installing appropriate APARs.
IBM AIX 5.1
IBM AIX 5.2
IBM AIX 5.3
References
IBM AIX CHCOD Local Privilege Escalation Vulnerability
References:
References: