IBM AIX 'qosmod' Local Buffer Overflow Vulnerability
BID:37412
Info
IBM AIX 'qosmod' Local Buffer Overflow Vulnerability
| Bugtraq ID: | 37412 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-4362 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 16 2009 12:00AM |
| Updated: | Apr 13 2015 09:05PM |
| Credit: | IBM |
| Vulnerable: |
IBM AIX 6.1 |
| Not Vulnerable: | |
Discussion
IBM AIX 'qosmod' Local Buffer Overflow Vulnerability
The IBM AIX 'qosmod' is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Further details have not been disclosed. We will update this BID as more information emerges.
A local attacker can exploit this issue to execute arbitrary code as an affected process, possibly with superuser privileges. Failed exploit attempts will likely cause denial-of-service conditions.
This issue affects AIX 6.1.
The IBM AIX 'qosmod' is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Further details have not been disclosed. We will update this BID as more information emerges.
A local attacker can exploit this issue to execute arbitrary code as an affected process, possibly with superuser privileges. Failed exploit attempts will likely cause denial-of-service conditions.
This issue affects AIX 6.1.
Exploit / POC
IBM AIX 'qosmod' Local Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
IBM AIX 'qosmod' Local Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
IBM AIX 'qosmod' Local Buffer Overflow Vulnerability
References:
References: