QID 330084

Date Published: 2021-07-12

QID 330084: IBM AIX Vulnerabilities in Ipd (lpd_advisory)

There are vulnerabilities in perl.rte that affect AIX.

Affected Platform:
AIX 7.1,7.2
Note: The detection requires root privileges to run "emgr -c" to check for patches. In absence of such privileges, the detection may not output actual results.

QID Detection Logic (Authenticated):
The detection checks for installed packages version via command : - "lslpp -L". It also checks for interim fixes installed using the command "emgr -c" or "instfix -k". The detection posts vulnerable if installed package version is less than patched version and interim fixes are also not installed.

On successful exploitation, IBM AIX could allow a local user with elevated privileges to exploit a vulnerability in the lpd daemon.

  • CVSS V3 rated as Medium - 4.4 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    The vendor has released fixes to resolve this vulnerability.

    CVEs related to QID 330084

    Software Advisories
    Advisory ID Software Component Link
    lpd_advisory URL Logo aix.software.ibm.com/aix/efixes/security/lpd_advisory.asc