IBM AIX Utape Command Local Privilege Escalation and Denial of Service Vulnerabilities
BID:20187
Info
IBM AIX Utape Command Local Privilege Escalation and Denial of Service Vulnerabilities
| Bugtraq ID: | 20187 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 25 2006 12:00AM |
| Updated: | Sep 26 2006 08:56PM |
| Credit: | The vendor reported these vulnerabilities. |
| Vulnerable: |
IBM AIX 5.3 IBM AIX 5.2 |
| Not Vulnerable: | |
Discussion
IBM AIX Utape Command Local Privilege Escalation and Denial of Service Vulnerabilities
AIX is prone to local privilege-escalation and denial-of-service vulnerabilities.
A local attacker can exploit these issues to execute arbitrary commands with root privileges or to overwrite arbitrary system files, resulting in denial-of-service conditions. To exploit this issue, an attacker must have both 'system group' and the diagnostics role.
AIX 5.2 and 5.3 are affected by this vulnerability.
AIX is prone to local privilege-escalation and denial-of-service vulnerabilities.
A local attacker can exploit these issues to execute arbitrary commands with root privileges or to overwrite arbitrary system files, resulting in denial-of-service conditions. To exploit this issue, an attacker must have both 'system group' and the diagnostics role.
AIX 5.2 and 5.3 are affected by this vulnerability.
Exploit / POC
IBM AIX Utape Command Local Privilege Escalation and Denial of Service Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution / Fix
IBM AIX Utape Command Local Privilege Escalation and Denial of Service Vulnerabilities
Solution:
The vendor has released fixes to address these issues. Please see the references for details.
IBM AIX 5.2
IBM AIX 5.3
Solution:
The vendor has released fixes to address these issues. Please see the references for details.
IBM AIX 5.2
-
IBM APAR: IY88641
http://www-1.ibm.com/support/docview.wss?uid=isg1IY88641 -
IBM utape_ifix.tar.Z
ftp://aix.software.ibm.com/aix/efixes/security/utape_ifix.tar.Z
IBM AIX 5.3
-
IBM utape_ifix.tar.Z
ftp://aix.software.ibm.com/aix/efixes/security/utape_ifix.tar.Z
References
IBM AIX Utape Command Local Privilege Escalation and Denial of Service Vulnerabilities
References:
References:
- AIX Homepage (IBM)