PT-2007-4293 · Ibm+1 · Aix+2
Publicado
2007-06-04
·
Atualizado
2012-10-31
·
CVE-2007-2996
CVSS v2.0
6.6
Média
| Vetor | AV:L/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
perl.rte versions 5.8.0.10 through 5.8.0.95 on IBM AIX 5.2
perl.rte versions 5.8.2.10 through 5.8.2.50 on AIX 5.3
Description:
The issue allows local users to gain privileges via unspecified vectors related to the installation and waiting for a legitimate user to execute a binary that ships with Perl.
Recommendations:
For perl.rte versions 5.8.0.10 through 5.8.0.95 on IBM AIX 5.2, update to a version outside of this range to resolve the issue.
For perl.rte versions 5.8.2.10 through 5.8.2.50 on AIX 5.3, update to a version outside of this range to resolve the issue.
As a temporary workaround, consider restricting access to the binaries that ship with Perl to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Aix
Perl
Perl.Rte