IBM AIX 'utape' Local Buffer Overflow Vulnerability
BID:27430
Info
IBM AIX 'utape' Local Buffer Overflow Vulnerability
| Bugtraq ID: | 27430 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0588 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 22 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | The vendor discovered this issue. |
| Vulnerable: |
IBM AIX 5.3 IBM AIX 5.2 |
| Not Vulnerable: | |
Discussion
IBM AIX 'utape' Local Buffer Overflow Vulnerability
IBM AIX is prone to a local buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Attackers can exploit this issue to execute arbitrary code with superuser privileges. Successful exploits will completely compromise affected computers. Failed exploit attempts will result in a denial of service.
NOTE: An attacker must be a member of the 'system' group to exploit this issue.
IBM AIX is prone to a local buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Attackers can exploit this issue to execute arbitrary code with superuser privileges. Successful exploits will completely compromise affected computers. Failed exploit attempts will result in a denial of service.
NOTE: An attacker must be a member of the 'system' group to exploit this issue.
Exploit / POC
IBM AIX 'utape' Local Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
References
IBM AIX 'utape' Local Buffer Overflow Vulnerability
References:
References:
- AIX Homepage (IBM)
- AIX utape buffer overflow (IBM)