vendor:
AIX
by:
LAST STAGE OF DELIRIUM
7.2
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: AIX
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: UNIX
2000
AIX Privilege Escalation Vulnerability
A vulnerability exists in the AIX Operating System distributed by IBM which could allow a user an elevation in priviledge. The problem occurs in the digest binary. It is reported that it is possible to overflow a buffer in the program and overwrite a pointer to the stack, which in turn can result in an overflow in a library referenced by the binary. The secondary overflow in the library makes it possible to overwrite other stack variables, including the return address. A malicious user could use this vulnerability to gain an elevation in priviledges, and potentially UID 0.
Mitigation:
Obtain the exact AIX OS level with the use of the uname -a or oslevel commands.