PT-2004-1653 · Ibm · Lvm For Aix
Published
2004-06-10
·
Updated
2017-07-11
·
CVE-2004-0544
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
LVM for AIX versions 5.1 through 5.2
Description
The issue is related to multiple buffer overflows that allow local users to gain privileges. This can be achieved via the putlvcb or getlvcb commands.
Recommendations
For LVM for AIX versions 5.1 through 5.2, consider restricting access to the putlvcb and getlvcb commands until a patch is available.
As a temporary workaround, limit the use of these commands to necessary users only.
Avoid using the putlvcb and getlvcb commands with untrusted input until the issue is resolved.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lvm For Aix