IBM AIX Getconf Local Buffer Overflow Vulnerability
BID:14959
Info
IBM AIX Getconf Local Buffer Overflow Vulnerability
| Bugtraq ID: | 14959 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-3060 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 28 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
IBM AIX 5.3 L IBM AIX 5.2.2 IBM AIX 5.2 L IBM AIX 5.1 L IBM AIX 5.3 IBM AIX 5.2 IBM AIX 5.1 |
| Not Vulnerable: | |
Discussion
IBM AIX Getconf Local Buffer Overflow Vulnerability
IBM AIX getconf is prone to a local buffer overflow vulnerability. This issue arises because the application fails to perform boundary checks prior to copying user-supplied data into insufficiently-sized memory buffers.
A successful attack allows arbitrary machine code execution with superuser privileges, due to the affected application being installed with setuid-superuser privileges.
IBM AIX getconf is prone to a local buffer overflow vulnerability. This issue arises because the application fails to perform boundary checks prior to copying user-supplied data into insufficiently-sized memory buffers.
A successful attack allows arbitrary machine code execution with superuser privileges, due to the affected application being installed with setuid-superuser privileges.
Exploit / POC
IBM AIX Getconf Local Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
IBM AIX Getconf Local Buffer Overflow Vulnerability
Solution:
The vendor has released an advisory, along with fixes to address this issue. Please see the referenced advisory for further information.
IBM AIX 5.2
IBM AIX 5.3
IBM AIX 5.2 L
IBM AIX 5.2.2
IBM AIX 5.3 L
Solution:
The vendor has released an advisory, along with fixes to address this issue. Please see the referenced advisory for further information.
IBM AIX 5.2
-
IBM IY73850: SECURITY: VULNERABILITIES IN GETCONF COMMAND
http://www-1.ibm.com/support/docview.wss?uid=isg1IY73850
IBM AIX 5.3
-
IBM IY73814: SECURITY: VULNERABILITIES IN GETCONF COMMAND
http://www-1.ibm.com/support/docview.wss?uid=isg1IY73814
IBM AIX 5.2 L
-
IBM IY73850: SECURITY: VULNERABILITIES IN GETCONF COMMAND
http://www-1.ibm.com/support/docview.wss?uid=isg1IY73850
IBM AIX 5.2.2
-
IBM IY73850: SECURITY: VULNERABILITIES IN GETCONF COMMAND
http://www-1.ibm.com/support/docview.wss?uid=isg1IY73850
IBM AIX 5.3 L
-
IBM IY73814: SECURITY: VULNERABILITIES IN GETCONF COMMAND
http://www-1.ibm.com/support/docview.wss?uid=isg1IY73814
References
IBM AIX Getconf Local Buffer Overflow Vulnerability
References:
References:
- AIX Homepage (IBM)
- IBM AIX swcons Commandline Argument Overflow (intropy
)