PT-2007-5534 · Ibm · Ibm Aix

Published

2007-08-15

·

Updated

2017-07-29

·

CVE-2007-4353

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM AIX versions 5.2 through 5.3
Description The issue involves multiple buffer overflows that allow local users in the system group to gain root privileges. This is achieved through unspecified vectors involving the chpath, rmpath, and devinstall programs in bos.rte.methods.
Recommendations For IBM AIX versions 5.2 and 5.3, consider restricting access to the chpath, rmpath, and devinstall programs in bos.rte.methods until a patch is available. As a temporary workaround, consider disabling the bos.rte.methods package to minimize the risk of exploitation. Restrict local users' access to the system group to prevent potential privilege escalation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-4353

Affected Products

Ibm Aix