IBM Snappd AIX Local Arbitrary Command Execution Vulnerability
BID:20193
Info
IBM Snappd AIX Local Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 20193 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 25 2006 12:00AM |
| Updated: | Sep 27 2006 05:26PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
IBM AIX 5.3 IBM AIX 5.2 |
| Not Vulnerable: | |
Discussion
IBM Snappd AIX Local Arbitrary Command Execution Vulnerability
IBM AIX is prone to an arbitrary-command-execution vulnerability.
An attacker can exploit this vulnerability to execute arbitrary commands with superuser privileges. A successful exploit would lead to a complete compromise of affected computers.
AIX versions 5.2 and 5.3 are vulnerable to this issue.
IBM AIX is prone to an arbitrary-command-execution vulnerability.
An attacker can exploit this vulnerability to execute arbitrary commands with superuser privileges. A successful exploit would lead to a complete compromise of affected computers.
AIX versions 5.2 and 5.3 are vulnerable to this issue.
Exploit / POC
IBM Snappd AIX Local Arbitrary Command Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
IBM Snappd AIX Local Arbitrary Command Execution Vulnerability
Solution:
The vendor has released an interim fix to address this issue. Please see the references for more information.
IBM AIX 5.2
IBM AIX 5.3
Solution:
The vendor has released an interim fix to address this issue. Please see the references for more information.
IBM AIX 5.2
-
IBM snappd_ifix.tar.Z
ftp://aix.software.ibm.com/aix/efixes/security/snappd_ifix.tar.Z -
IBM 1IY88820
http://www-1.ibm.com/support/docview.wss?uid=isg1IY88820
IBM AIX 5.3
-
IBM 1IY88818
http://www-1.ibm.com/support/docview.wss?uid=isg1IY88818 -
IBM snappd_ifix.tar.Z
ftp://aix.software.ibm.com/aix/efixes/security/snappd_ifix.tar.Z