PT-2007-4293 · Ibm+1 · Aix+2

Publicado

2007-06-04

·

Atualizado

2012-10-31

·

CVE-2007-2996

CVSS v2.0

6.6

Média

VetorAV:L/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: perl.rte versions 5.8.0.10 through 5.8.0.95 on IBM AIX 5.2 perl.rte versions 5.8.2.10 through 5.8.2.50 on AIX 5.3
Description: The issue allows local users to gain privileges via unspecified vectors related to the installation and waiting for a legitimate user to execute a binary that ships with Perl.
Recommendations: For perl.rte versions 5.8.0.10 through 5.8.0.95 on IBM AIX 5.2, update to a version outside of this range to resolve the issue. For perl.rte versions 5.8.2.10 through 5.8.2.50 on AIX 5.3, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the binaries that ship with Perl to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2996

Produtos afetados

Aix
Perl
Perl.Rte