IBM AIX RCP Utility Local Buffer Overrun Vulnerability
BID:9078
Info
IBM AIX RCP Utility Local Buffer Overrun Vulnerability
| Bugtraq ID: | 9078 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0954 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 20 2003 12:00AM |
| Updated: | Jul 12 2009 12:56AM |
| Credit: | This issue was discovered internally by IBM. |
| Vulnerable: |
IBM AIX 4.3.3 IBM AIX 5.2 IBM AIX 5.1 |
| Not Vulnerable: | |
Discussion
IBM AIX RCP Utility Local Buffer Overrun Vulnerability
IBM has announced the existence of a local buffer overrun vulnerability in the rcp utility that could be exploited to gain root privileges. The precise details regarding this condition are unknown, however it is likely that the problem occurs due to insufficient bounds checking when handling command-line or environment data.
IBM has announced the existence of a local buffer overrun vulnerability in the rcp utility that could be exploited to gain root privileges. The precise details regarding this condition are unknown, however it is likely that the problem occurs due to insufficient bounds checking when handling command-line or environment data.
Exploit / POC
IBM AIX RCP Utility Local Buffer Overrun Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
IBM AIX RCP Utility Local Buffer Overrun Vulnerability
Solution:
IBM is said to have released APARs to address this issue. Further information can be obtained by contacting the vendor.
IBM AIX 5.1
IBM AIX 5.2
IBM AIX 4.3.3
Solution:
IBM is said to have released APARs to address this issue. Further information can be obtained by contacting the vendor.
IBM AIX 5.1
IBM AIX 5.2
IBM AIX 4.3.3