PT-2015-4115 · Ibm · Ibm Aix+1

S2 Crew

·

Publicado

2015-01-13

·

Atualizado

2021-08-31

·

CVE-2014-8904

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM AIX versions 5.3, 6.1, and 7.1 VIOS versions 2.2.x
Description The issue allows local users to gain privileges via a crafted DBGCMD LQUERYLV environment-variable value when running the lquerylv command. This could potentially allow a local user to gain root privileges.
Recommendations For IBM AIX versions 5.3, 6.1, and 7.1, consider restricting access to the lquerylv command until a patch is available. For VIOS versions 2.2.x, avoid using the DBGCMD LQUERYLV environment variable in the lquerylv command until the issue is resolved. As a temporary workaround, consider disabling the lquerylv command until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-8904

Produtos afetados

Ibm Aix
Vios