Vulnerability Bulletins |
Ejecución de código en el comando reboot de IBM AIX |
|
Vulnerability classification |
|
| Property | Value |
| Confidence level | Oficial |
| Impact | Compromiso Root |
| Dificulty | Experto |
| Required attacker level | Acceso remoto con cuenta |
System information |
|
| Property | Value |
| Affected manufacturer | UNIX |
| Affected software |
IBM AIX 5.2 IBM AIX 5.3 |
Description |
|
|
Se ha descubierto una vulnerabilidad en IBM AIX 5.2, 5.3. La vulnerabilidad reside en un error de tipo desbordamiento de pila en el comando "reboot". Un atacante local en el grupo "shutdown" podría ejecutar código arbitrario con privilegios de root mediante métodos no especificados. |
|
Solution |
|
|
Actualización de software IBM AIX 5.2.0 - APAR IZ15479 http://www.ibm.com/support/docview.wss?uid=isg1IZ15479 AIX 5.3.0 - APAR IZ15480 (Disponible el 17/03/2008) http://www.ibm.com/support/docview.wss?uid=isg1IZ15480 |
|
Standar resources |
|
| Property | Value |
| CVE | CVE-2008-1601 |
| BID | |
Other resources |
|
|
IBM Security Advisory http://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&heading=AIX61&path=/200803/SECURITY/20080311/datafile141218 |
|
Version history |
||
| Version | Comments | Date |
| 1.0 | Aviso emitido | 2008-03-12 |
| 1.1 | CVE añadido | 2008-08-21 |






