AIX lchangelv Buffer Overflow Vulnerability
BID:389
Info
AIX lchangelv Buffer Overflow Vulnerability
| Bugtraq ID: | 389 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-1999-0122 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 21 1997 12:00AM |
| Updated: | Jul 17 2007 10:06AM |
| Credit: | This bug was posted to tbe Bugtraq mailing list by Bryan P. Self <[email protected]> Mon, 21 Jul 1997. |
| Vulnerable: |
IBM AIX 4.2 IBM AIX 4.1.5 IBM AIX 4.1.4 IBM AIX 4.1.3 IBM AIX 4.1.2 IBM AIX 4.1.1 IBM AIX 4.1 |
| Not Vulnerable: |
IBM AIX 4.3.2 IBM AIX 4.3 IBM AIX 4.2.1 IBM AIX 3.2.5 IBM AIX 3.2.4 IBM AIX 3.2 |
Discussion
AIX lchangelv Buffer Overflow Vulnerability
A buffer overflow can occur in lchangelv under some versions of AIX. Note that an attacker must already have the GID or EGID of 'system' to execute lchangelv.
Because lchangelv is SUID root, this overflow will grant the attacker root privileges.
A buffer overflow can occur in lchangelv under some versions of AIX. Note that an attacker must already have the GID or EGID of 'system' to execute lchangelv.
Because lchangelv is SUID root, this overflow will grant the attacker root privileges.
Exploit / POC
AIX lchangelv Buffer Overflow Vulnerability
The following exploit code is available.
The following exploit code is available.
Solution / Fix
AIX lchangelv Buffer Overflow Vulnerability
Solution:
IBM has made the following APARs available to address this problem:
AIX 4.2
----------
APAR # IX64204
AIX 4.1
---------
APAR # IX64203
Solution:
IBM has made the following APARs available to address this problem:
AIX 4.2
----------
APAR # IX64204
AIX 4.1
---------
APAR # IX64203
References
AIX lchangelv Buffer Overflow Vulnerability
References:
References:
- AIX Fix Distribution Service (IBM)
- IBM Support Databases (IBM)