PT-2015-4115 · Ibm · Ibm Aix+1
S2 Crew
·
Publicado
2015-01-13
·
Atualizado
2021-08-31
·
CVE-2014-8904
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM AIX versions 5.3, 6.1, and 7.1
VIOS versions 2.2.x
Description
The issue allows local users to gain privileges via a crafted
DBGCMD LQUERYLV environment-variable value when running the lquerylv command. This could potentially allow a local user to gain root privileges.Recommendations
For IBM AIX versions 5.3, 6.1, and 7.1, consider restricting access to the lquerylv command until a patch is available.
For VIOS versions 2.2.x, avoid using the
DBGCMD LQUERYLV environment variable in the lquerylv command until the issue is resolved.
As a temporary workaround, consider disabling the lquerylv command until a patch is available.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Aix
Vios