IBM AIX tsm Utility Local Format String Vulnerability
BID:8648
Info
IBM AIX tsm Utility Local Format String Vulnerability
| Bugtraq ID: | 8648 |
| Class: | Design Error |
| CVE: |
CVE-2003-0784 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 18 2003 12:00AM |
| Updated: | Jul 11 2009 11:56PM |
| Credit: | This vulnerability was announced by IBM in a security advisory. |
| Vulnerable: |
IBM AIX 4.3.3 IBM AIX 5.2 IBM AIX 5.1 |
| Not Vulnerable: | |
Discussion
IBM AIX tsm Utility Local Format String Vulnerability
A format string vulnerability has been discovered in the IBM AIX tsm command which may allow for local or remote root exploitation. Due to a variety of software implementing the use of the tsm utility on AIX systems, such as login, su, and passwd, a local attacker may be capable of exploiting this issue through a variety of methods. Successful exploitation will ultimately allow for an attacker to gain root privileges.
Only IBM AIX 5.2 appears to be affected by the issue.
A format string vulnerability has been discovered in the IBM AIX tsm command which may allow for local or remote root exploitation. Due to a variety of software implementing the use of the tsm utility on AIX systems, such as login, su, and passwd, a local attacker may be capable of exploiting this issue through a variety of methods. Successful exploitation will ultimately allow for an attacker to gain root privileges.
Only IBM AIX 5.2 appears to be affected by the issue.
Exploit / POC
Solution / Fix
IBM AIX tsm Utility Local Format String Vulnerability
Solution:
A fix has been released by IBM.
IBM AIX 5.2
Solution:
A fix has been released by IBM.
IBM AIX 5.2
-
IBM IY47764
http://www-1.ibm.com/support/
References
IBM AIX tsm Utility Local Format String Vulnerability
References:
References: