PT-2012-2836 · Ibm · Ibm Aix+1
Publicado
2012-05-04
·
Atualizado
2017-12-07
·
CVE-2012-0745
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM AIX versions 5.3, 6.1, and 7.1
VIOS versions 2.1.0.10 through 2.2.1.3
Description
The issue is related to the
getpwnam function, which does not properly interact with customer-extended LDAP user filtering. This allows local users to gain privileges via unspecified vectors.Recommendations
For IBM AIX versions 5.3, 6.1, and 7.1, consider restricting access to the
getpwnam function until a patch is available.
For VIOS versions 2.1.0.10 through 2.2.1.3, consider disabling the use of customer-extended LDAP user filtering as a temporary workaround.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Aix
Vios