AIX xdat Buffer Overflow Vulnerability
BID:449
Info
AIX xdat Buffer Overflow Vulnerability
| Bugtraq ID: | 449 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 22 1997 12:00AM |
| Updated: | Oct 22 1997 12:00AM |
| Credit: | This bug was found by Bryan P. Self Bryan P. Self <[email protected]> and was released as IBM ERS ERS-SVA-E01-1997:004.1 on 21 October 1997. |
| Vulnerable: |
IBM AIX 4.2.1 IBM AIX 4.2 IBM AIX 4.1.5 IBM AIX 4.1.4 IBM AIX 4.1.3 IBM AIX 4.1.2 IBM AIX 4.1.1 IBM AIX 4.1 |
| Not Vulnerable: |
IBM AIX 4.3.2 IBM AIX 4.3 |
Discussion
AIX xdat Buffer Overflow Vulnerability
The "xdat" command shipped with AIX version 4 does not check the length of the "TZ" environment variable and is therefore vulnerable to a classic buffer overflow attack.
The "xdat" command shipped with AIX version 4 does not check the length of the "TZ" environment variable and is therefore vulnerable to a classic buffer overflow attack.
Exploit / POC
AIX xdat Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
AIX xdat Buffer Overflow Vulnerability
Solution:
IBM has released the following APAR'S to address this problem:
AIX 4.3
---------
APAR # IX72020
AIX 4.2
----------
APAR # IX72021
Solution:
IBM has released the following APAR'S to address this problem:
AIX 4.3
---------
APAR # IX72020
AIX 4.2
----------
APAR # IX72021
References
AIX xdat Buffer Overflow Vulnerability
References:
References:
- AIX Fix Distribution Service (IBM)
- IBM Support Databases (IBM)