QID 330152

Date Published: 2023-11-20

QID 330152: IBM AIX Multiple Vulnerabilities (python_advisory6)

A vulnerability in Python could allow a non-privileged local user to cause a denial of service (CVE-2023-45167) and a remote attacker to cause a security restrictions bypass (CVE-2023-40217)

Affected Version
AIX 7.3
QID Detection Logic (Authenticated):
The detection checks for installed packages version via command : lslpp -L | grep -i python3.9.base;. The detection posts vulnerable if installed package version is less than patched version

Successful exploitation of the vulnerability may allow remote attacker to bypass security restrictions and denial of service

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    The vendor has released fixes to python_advisory6 this vulnerability.

    CVEs related to QID 330152

    Software Advisories
    Advisory ID Software Component Link
    python_advisory6 URL Logo aix.software.ibm.com/aix/efixes/security/python_advisory6.asc