IBM AIX UUCP Local Privilege Escalation Vulnerability
BID:20196
Info
IBM AIX UUCP Local Privilege Escalation Vulnerability
| Bugtraq ID: | 20196 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 25 2006 12:00AM |
| Updated: | Sep 25 2006 12:00AM |
| Credit: | The vendor has disclosed this issue. |
| Vulnerable: |
IBM AIX 5.3 IBM AIX 5.2 |
| Not Vulnerable: | |
Discussion
IBM AIX UUCP Local Privilege Escalation Vulnerability
IBM AIX is prone to a local privilege-escalation vulnerability.
A local attacker may be able to exploit this issue to execute arbitrary commands with 'uucp' privileges. This may aid malicious users in further attacks.
IBM AIX versions 5.2 and 5.3 are vulnerable to this issue.
IBM AIX is prone to a local privilege-escalation vulnerability.
A local attacker may be able to exploit this issue to execute arbitrary commands with 'uucp' privileges. This may aid malicious users in further attacks.
IBM AIX versions 5.2 and 5.3 are vulnerable to this issue.
Exploit / POC
IBM AIX UUCP Local Privilege Escalation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
IBM AIX UUCP Local Privilege Escalation Vulnerability
Solution:
IBM has released an advisory and fixes to address this issue. Please see the references for more information.
IBM AIX 5.2
IBM AIX 5.3
Solution:
IBM has released an advisory and fixes to address this issue. Please see the references for more information.
IBM AIX 5.2
-
IBM uucp_ifix.tar.Z
ftp://aix.software.ibm.com/aix/efixes/security/uucp_ifix.tar.Z -
IBM IY88565
http://www.ibm.com/
IBM AIX 5.3
-
IBM uucp_ifix.tar.Z
ftp://aix.software.ibm.com/aix/efixes/security/uucp_ifix.tar.Z -
IBM IY88614
http://www.ibm.com/