QID 330136
Date Published: 2023-04-26
QID 330136: IBM AIX Runtime Services Library (librts) Arbitrary Command Execution Vulnerability (librts_advisory)
A vulnerability in the AIX runtime services library could allow a non-privileged local user to execute arbitrary commands (CVE-2023-26286).
Affected Platform:
AIX 7.1, 7.2, 7.3
QID Detection Logic (Authenticated):
The detection checks for installed packages version via command lslpp -L | grep -i bos.mp64. It also checks for interim fixes installed The detection posts vulnerable if installed package version is less than patched version and interim fixes are also not installed.
Successful exploit could allow a non-privileged local user to execute arbitrary commands
Solution
The vendor has released fixes to librts_advisory this vulnerability.
Vendor References
- librts_advisory -
aix.software.ibm.com/aix/efixes/security/librts_advisory.asc
CVEs related to QID 330136
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| librts_advisory |
|