IBM AIX Slip.Login Local Privilege Escalation Vulnerability
BID:20191
Info
IBM AIX Slip.Login Local Privilege Escalation Vulnerability
| Bugtraq ID: | 20191 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 25 2006 12:00AM |
| Updated: | Sep 26 2006 08:21PM |
| Credit: | This issue was disclosed by the vendor. |
| Vulnerable: |
IBM AIX 5.3 L IBM AIX 5.2 L IBM AIX 5.3 IBM AIX 5.2 |
| Not Vulnerable: | |
Discussion
IBM AIX Slip.Login Local Privilege Escalation Vulnerability
IBM AIX is prone to a privilege-escalation vulnerability in '/etc/slip.login'. Exploiting this issue may allow an unprivileged user to execute arbitrary code with superuser privileges.
IBM AIX is prone to a privilege-escalation vulnerability in '/etc/slip.login'. Exploiting this issue may allow an unprivileged user to execute arbitrary code with superuser privileges.
Exploit / POC
IBM AIX Slip.Login Local Privilege Escalation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
IBM AIX Slip.Login Local Privilege Escalation Vulnerability
Solution:
IBM has released an advisory and APAR fixes to address this issue. Please see the references for more information.
IBM AIX 5.2
IBM AIX 5.3
Solution:
IBM has released an advisory and APAR fixes to address this issue. Please see the references for more information.
IBM AIX 5.2
-
IBM sliplogin_ifix.tar.Z
ftp://aix.software.ibm.com/aix/efixes/security/sliplogin_ifix.tar.Z -
IBM IY88566
http://www.ibm.com
IBM AIX 5.3
-
IBM sliplogin_ifix.tar.Z
ftp://aix.software.ibm.com/aix/efixes/security/sliplogin_ifix.tar.Z -
IBM IY88615
http://www.ibm.com