vendor:
AIX
by:
LAST STAGE OF DELIRIUM
7.2
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: AIX
Affected Version From: AIX 4.2.1
Affected Version To: AIX 4.3.x
Patch Exists: YES
Related CWE: N/A
CPE: o:ibm:aix:4.2.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: PowerPC/POWER
2000
AIX portmir Command Buffer Overflow Vulnerability
AIX version 4.2.1 introduced a new command titled 'portmir'. This new program had two notable vulnerabilites. First it contained a buffer overflow which allowed malicious users to obtain root privileges. Secondly it wrote it's log files to a world readable directly thereby exposing security relavent information.
Mitigation:
Upgrade to the latest version of AIX.