IBM AIX 'man' Local Privilege Escalation Vulnerability
BID:28180
Info
IBM AIX 'man' Local Privilege Escalation Vulnerability
| Bugtraq ID: | 28180 |
| Class: | Design Error |
| CVE: |
CVE-2008-1274 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 10 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
IBM AIX 6.1 |
| Not Vulnerable: | |
Discussion
IBM AIX 'man' Local Privilege Escalation Vulnerability
IBM AIX is prone to a local privilege-escalation vulnerability because it fails to specify full paths to executables.
Attackers can exploit this issue to execute code with the privileges of other users on affected computers.
IBM AIX is prone to a local privilege-escalation vulnerability because it fails to specify full paths to executables.
Attackers can exploit this issue to execute code with the privileges of other users on affected computers.
Exploit / POC
IBM AIX 'man' Local Privilege Escalation Vulnerability
To exploit this issue, attackers can use readily available utilities.
To exploit this issue, attackers can use readily available utilities.
Solution / Fix
IBM AIX 'man' Local Privilege Escalation Vulnerability
Solution:
The vendor released an advisory and fixes to address this issue. Please see the references for more information.
IBM AIX 6.1
Solution:
The vendor released an advisory and fixes to address this issue. Please see the references for more information.
IBM AIX 6.1
References
IBM AIX 'man' Local Privilege Escalation Vulnerability
References:
References: