PT-2015-4115 · Ibm · Ibm Aix+1
S2 Crew
·
Published
2015-01-13
·
Updated
2021-08-31
·
CVE-2014-8904
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM AIX versions 5.3, 6.1, and 7.1
VIOS versions 2.2.x
Description
The issue allows local users to gain privileges via a crafted
DBGCMD LQUERYLV environment-variable value when running the lquerylv command. This could potentially allow a local user to gain root privileges.Recommendations
For IBM AIX versions 5.3, 6.1, and 7.1, consider restricting access to the lquerylv command until a patch is available.
For VIOS versions 2.2.x, avoid using the
DBGCMD LQUERYLV environment variable in the lquerylv command until the issue is resolved.
As a temporary workaround, consider disabling the lquerylv command until a patch is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Aix
Vios