|
|
|
![]() |
Vulnerability Note VU#886953IBM AIX setsenv buffer overflowOverviewThere is a buffer overflow in the IBM AIX setsenv command that may allow local attackers to gain root privileges.I. DescriptionThe setsenv command is used to set protected state environment variables. There is a buffer overflow in a variable value parameter to the setsenv command on IBM AIX systems. An exploit for this vulnerability is publicly available, and is reported to have been used to compromise systems.II. ImpactAn attacker with access to a local user account can execute arbitrary code on the vulnerable system as root.III. SolutionApply a PatchIBM has released patches to correct this problem. For AIX version 4.2, system adminstrators should apply APAR#IY10721. For AIX version 4.3, system administrators should apply APAR#IY08812.
References
This document was written by Cory F. Cohen.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||