PT-2014-5067 · Ibm · Aix+2
Published
2014-06-30
·
Updated
2021-08-31
·
CVE-2014-3074
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM AIX versions 6.1 through 7.1
VIOS versions 2.2.x
Description
The issue allows local users to create a mode-666 root-owned file and gain privileges by setting crafted
MALLOCOPTIONS and MALLOCBUCKETS environment-variable values and then executing a setuid program. Additionally, in AIX 6.1 and above, a local user can exploit this error using the LIB INIT DBG and LIB INIT DBG FILE environment variables. This can lead to privilege escalation via arbitrary file writes with elevated privileges programs.Recommendations
For IBM AIX versions 6.1 through 7.1, consider disabling the setuid programs that can be exploited with crafted
MALLOCOPTIONS and MALLOCBUCKETS environment-variable values until a patch is available.
For VIOS versions 2.2.x, restrict access to the runtime linker to minimize the risk of exploitation.
As a temporary workaround, consider restricting the use of the LIB INIT DBG and LIB INIT DBG FILE environment variables in AIX 6.1 and above until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aix
Ibm Aix
Vios