PT-2015-4115 · Ibm · Ibm Aix+1

S2 Crew

·

Published

2015-01-13

·

Updated

2021-08-31

·

CVE-2014-8904

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM AIX versions 5.3, 6.1, and 7.1 VIOS versions 2.2.x
Description The issue allows local users to gain privileges via a crafted DBGCMD LQUERYLV environment-variable value when running the lquerylv command. This could potentially allow a local user to gain root privileges.
Recommendations For IBM AIX versions 5.3, 6.1, and 7.1, consider restricting access to the lquerylv command until a patch is available. For VIOS versions 2.2.x, avoid using the DBGCMD LQUERYLV environment variable in the lquerylv command until the issue is resolved. As a temporary workaround, consider disabling the lquerylv command until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-8904

Affected Products

Ibm Aix
Vios