IBM AIX Debug Malloc Tools Local Buffer Overflow Vulnerability
BID:15881
Info
IBM AIX Debug Malloc Tools Local Buffer Overflow Vulnerability
| Bugtraq ID: | 15881 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 15 2005 12:00AM |
| Updated: | Dec 15 2005 12:00AM |
| Credit: | This vulnerability was reported to the vendor by David Litchfield of NGS Software. |
| Vulnerable: |
IBM AIX 5.3 L IBM AIX 5.3 |
| Not Vulnerable: | |
Discussion
IBM AIX Debug Malloc Tools Local Buffer Overflow Vulnerability
IBM AIX's malloc debugging tools are prone to a local buffer overflow vulnerability. This issue arises because the software fails to perform boundary checks prior to copying user-supplied data into insufficiently-sized memory buffers.
A successful attack allows arbitrary machine code execution with superuser privileges.
IBM AIX's malloc debugging tools are prone to a local buffer overflow vulnerability. This issue arises because the software fails to perform boundary checks prior to copying user-supplied data into insufficiently-sized memory buffers.
A successful attack allows arbitrary machine code execution with superuser privileges.
Exploit / POC
IBM AIX Debug Malloc Tools Local Buffer Overflow Vulnerability
The vendor states that exploits for this vulnerability may be publicly available. Symantec has not been able to verify this at this time.
--
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
The vendor states that exploits for this vulnerability may be publicly available. Symantec has not been able to verify this at this time.
--
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
IBM AIX Debug Malloc Tools Local Buffer Overflow Vulnerability
Solution:
The vendor has released an advisory, along with interim fixes to address this issue. These interim fixes are available from the following location:
ftp://aix.software.ibm.com/aix/efixes/security/dbgmalloc_ifix.tar.Z
The vendor states that the following fix should be available approximately 30 Jan, 2006:
APAR number for AIX 5.3.0: IY78227
Please see the referenced advisory for further information on obtaining and applying the interim fixes.
Solution:
The vendor has released an advisory, along with interim fixes to address this issue. These interim fixes are available from the following location:
ftp://aix.software.ibm.com/aix/efixes/security/dbgmalloc_ifix.tar.Z
The vendor states that the following fix should be available approximately 30 Jan, 2006:
APAR number for AIX 5.3.0: IY78227
Please see the referenced advisory for further information on obtaining and applying the interim fixes.
References
IBM AIX Debug Malloc Tools Local Buffer Overflow Vulnerability
References:
References:
- AIX Homepage (IBM)
- An Introduction to Heap overflows on AIX 5.3L (David Litchfield)
- Patches available for IBM AIX flaws ("NGSSoftware Insight Security Research"
)