QID 330130
Date Published: 2023-03-08
QID 330130: IBM AIX Arbitrary Code Execution Vulnerability in libxml2 (libxml2_advisory3)
AIX is vulnerable to a arbitrary code execution due to libxml2
Affected Platform:
AIX 7.2, 7.3
QID Detection Logic (Authenticated):
The detection checks for installed packages version via command : lslpp -L | grep -i bos.rte.control It also checks for interim fixes installed using the command "
emgr -c; or instfix -k. The detection posts vulnerable if installed package version is less than patched version and interim fixes are also not installed.
On successful exploitation IBM AIX could allow a local user to exploit a vulnerability in the libxml2 to cause code execution.
Solution
The vendor has released fixes to AIX advisory this vulnerability.
Vendor References
- libxml2_advisory4 -
aix.software.ibm.com/aix/efixes/security/libxml2_advisory4.asc
CVEs related to QID 330130
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| libxml2_advisory4 |
|