IBM AIX Mkvg Command Local Privilege Escalation Vulnerability
BID:20197
CVE-2006-4416 |Info
IBM AIX Mkvg Command Local Privilege Escalation Vulnerability
| Bugtraq ID: | 20197 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 25 2006 12:00AM |
| Updated: | Sep 26 2006 09:11PM |
| Credit: | The vendor reported this vulnerability. |
| Vulnerable: |
IBM AIX 5.3 IBM AIX 5.2 |
| Not Vulnerable: | |
Discussion
IBM AIX Mkvg Command Local Privilege Escalation Vulnerability
AIX is prone to a local privilege-escalation vulnerability
A local attacker can exploit this issue to execute arbitrary commands with superuser privileges on the affected computer. To exploit this issue, the attacker must have 'system group' permissions.
AIX 5.2 and 5.3 are affected by this vulnerability.
AIX is prone to a local privilege-escalation vulnerability
A local attacker can exploit this issue to execute arbitrary commands with superuser privileges on the affected computer. To exploit this issue, the attacker must have 'system group' permissions.
AIX 5.2 and 5.3 are affected by this vulnerability.
Exploit / POC
IBM AIX Mkvg Command Local Privilege Escalation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution / Fix
IBM AIX Mkvg Command Local Privilege Escalation Vulnerability
Solution:
The vendor has released fixes to address these issues. Please see the references for more information.
IBM AIX 5.2
IBM AIX 5.3
Solution:
The vendor has released fixes to address these issues. Please see the references for more information.
IBM AIX 5.2
-
IBM mkvg_ifix.tar.Z
ftp://aix.software.ibm.com/aix/efixes/security/mkvg_ifix.tar.Z -
IBM IY88722
http://www-1.ibm.com/support/docview.wss?uid=isg1IY88722
IBM AIX 5.3
-
IBM mkvg_ifix.tar.Z
ftp://aix.software.ibm.com/aix/efixes/security/mkvg_ifix.tar.Z -
IBM IY88699
http://www-1.ibm.com/support/docview.wss?uid=isg1IY88699