PT-2007-2124 · None+1 · Rdist+5

Published

2007-02-03

·

Updated

2017-07-29

·

CVE-2007-0670

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IBM AIX versions 5.2 through 5.3
Description The issue is related to a buffer overflow in the bos.rte.libc component, which can be exploited by local users to execute arbitrary code. This can potentially be achieved through the use of "r-commands", including rdist, rsh, rcp, rsync, and rlogin.
Recommendations For IBM AIX versions 5.2 and 5.3, consider restricting access to the "r-commands" until a fix is available. As a temporary workaround, consider disabling the use of rdist, rsh, rcp, rsync, and rlogin to minimize the risk of exploitation.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-0670

Affected Products

Ibm Aix
Rcp
Rdist
Rlogin
Rsh
Rsync