PT-2007-5534 · Ibm · Ibm Aix
Published
2007-08-15
·
Updated
2017-07-29
·
CVE-2007-4353
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM AIX versions 5.2 through 5.3
Description
The issue involves multiple buffer overflows that allow local users in the system group to gain root privileges. This is achieved through unspecified vectors involving the chpath, rmpath, and devinstall programs in bos.rte.methods.
Recommendations
For IBM AIX versions 5.2 and 5.3, consider restricting access to the chpath, rmpath, and devinstall programs in bos.rte.methods until a patch is available.
As a temporary workaround, consider disabling the bos.rte.methods package to minimize the risk of exploitation.
Restrict local users' access to the system group to prevent potential privilege escalation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Aix