vendor:
AIX Printing Subsystem
by:
LAST STAGE OF DELIRIUM
7.2
CVSS
HIGH
Stack Overrun
119
CWE
Product Name: AIX Printing Subsystem
Affected Version From: AIX 4.1
Affected Version To: AIX 4.3
Patch Exists: YES
Related CWE: N/A
CPE: o:ibm:aix:4.3
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: PowerPC/POWER
2000
AIX Printing Subsystem ‘piomkapqd’ Local Privilege Escalation Vulnerability
The 'piomkapqd' utility is a component of the AIX printing subsystem. By default, it is installed setgid and owned by the 'printk' group. 'piomkapqd' contains a locally exploitable stack overrun condition in it's handling of command line parameters. Local users may be able to gain group 'printk' privileges if this vulnerability is exploited. It may be possible to elevate to root from this point by exploiting vulnerabilities in other components of the printing subsystem.
Mitigation:
Upgrade to the latest version of AIX Printing Subsystem.