AIX portmir Buffer Overflow & Insecure Temporary File Creation Vulnerabilities
BID:385
Info
AIX portmir Buffer Overflow & Insecure Temporary File Creation Vulnerabilities
| Bugtraq ID: | 385 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 29 1997 12:00AM |
| Updated: | Oct 29 1997 12:00AM |
| Credit: | This vulnerability was initially published by the IBM ERS Team to the Bugtraq mailing list as ERS-SVA-E01-1997:006.1 on 29 October 1997. |
| Vulnerable: |
IBM AIX 4.2.1 |
| Not Vulnerable: |
IBM AIX 4.3.2 IBM AIX 4.3 IBM AIX 4.2 IBM AIX 4.1.5 IBM AIX 4.1.4 IBM AIX 4.1.3 IBM AIX 4.1.1 IBM AIX 4.1 IBM AIX 3.2.5 |
Discussion
AIX portmir Buffer Overflow & Insecure Temporary File Creation Vulnerabilities
AIX version 4.2.1 introduced a new command titled 'portmir'. This new program had two notable vulnerabilites. First it contained a buffer overflow which allowed malicious users to obtain root privileges. Secondly it wrote it's log files to a world readable directly thereby exposing security relavent information.
AIX version 4.2.1 introduced a new command titled 'portmir'. This new program had two notable vulnerabilites. First it contained a buffer overflow which allowed malicious users to obtain root privileges. Secondly it wrote it's log files to a world readable directly thereby exposing security relavent information.
Exploit / POC
AIX portmir Buffer Overflow & Insecure Temporary File Creation Vulnerabilities
Last Stage of Delerium has published exploit code:
Last Stage of Delerium has published exploit code:
Solution / Fix
AIX portmir Buffer Overflow & Insecure Temporary File Creation Vulnerabilities
Solution:
IBM has released the following APAR to address this problem:
Solution:
IBM has released the following APAR to address this problem:
References
AIX portmir Buffer Overflow & Insecure Temporary File Creation Vulnerabilities
References:
References:
- AIX Fix Distribution Service (IBM)
- IBM Support Databases (IBM)