AIX uucp Vulnerability
BID:38
Info
AIX uucp Vulnerability
| Bugtraq ID: | 38 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 19 1992 12:00AM |
| Updated: | Mar 19 1992 12:00AM |
| Credit: | This vulnerability was published by CERT/CC as CA-92.06 AIX UUCP Vulnerability. |
| Vulnerable: |
IBM AIX 3.1 IBM AIX 2.2.1 IBM AIX 1.3 |
| Not Vulnerable: |
IBM AIX 3.2 |
Discussion
AIX uucp Vulnerability
A vulnerability exists with the UUCP software in versions of AIX up to 2007. The vulnerability does not exist in AIX 3.2.
Previous versions, except AIX 3.2, of the UUCP software contained incorrectly configured versions of various files.
Local users can execute unauthorized commands and gain unauthorized root access.
A vulnerability exists with the UUCP software in versions of AIX up to 2007. The vulnerability does not exist in AIX 3.2.
Previous versions, except AIX 3.2, of the UUCP software contained incorrectly configured versions of various files.
Local users can execute unauthorized commands and gain unauthorized root access.
Exploit / POC
AIX uucp Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
AIX uucp Vulnerability
Solution:
IBM issued the following APAR to address this problem:
AIX 3.X
---------
APAR # IX18516
Solution:
IBM issued the following APAR to address this problem:
AIX 3.X
---------
APAR # IX18516