IBM AIX Named8 Local Privilege Escalation Vulnerability
BID:20198
CVE-2006-5003 |Info
IBM AIX Named8 Local Privilege Escalation Vulnerability
| Bugtraq ID: | 20198 |
| Class: | Unknown |
| CVE: |
CVE-2006-5003 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 25 2006 12:00AM |
| Updated: | Feb 20 2007 08:28PM |
| Credit: | The vendor reported this vulnerability. |
| Vulnerable: |
IBM AIX 5.3 IBM AIX 5.2 |
| Not Vulnerable: | |
Discussion
IBM AIX Named8 Local Privilege Escalation Vulnerability
AIX is prone to a local privilege-escalation vulnerability
A local attacker can exploit this issue to execute arbitrary commands with superuser privileges on the affected computer. The attacker must have 'system group' permissions to exploit this issue.
AIX 5.2 and 5.3 are affected by this vulnerability.
AIX is prone to a local privilege-escalation vulnerability
A local attacker can exploit this issue to execute arbitrary commands with superuser privileges on the affected computer. The attacker must have 'system group' permissions to exploit this issue.
AIX 5.2 and 5.3 are affected by this vulnerability.
Exploit / POC
IBM AIX Named8 Local Privilege Escalation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
IBM AIX Named8 Local Privilege Escalation Vulnerability
Solution:
The vendor has released fixes to address these issues. Please see the reference section for further information.
IBM AIX 5.2
IBM AIX 5.3
Solution:
The vendor has released fixes to address these issues. Please see the reference section for further information.
IBM AIX 5.2
-
IBM IY76102
http://www.ibm.com/servers/eserver/support/unixservers/aixfixes.html -
IBM named8_ifix.tar.Z
ftp://aix.software.ibm.com/aix/efixes/security/named8_ifix.tar.Z
IBM AIX 5.3
-
IBM IY76483
http://www.ibm.com/servers/eserver/support/unixservers/aixfixes.html -
IBM named8_ifix.tar.Z
ftp://aix.software.ibm.com/aix/efixes/security/named8_ifix.tar.Z