Vulnerability Name: | CVE-2005-2233 (CCN-20936) | ||||||||
Assigned: | 2005-06-06 | ||||||||
Published: | 2005-06-06 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | Buffer overflow in multiple "p" commands in IBM AIX 5.1, 5.2 and 5.3 might allow local users to execute arbitrary code via long command line arguments to (1) penable or other hard-linked files including (2) pdisable, (3) pstart, (4) phold, (5) pdelay, or (6) pshare. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2005-2233 Source: CCN Type: SA15636 AIX Multiple Privilege Escalation Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 15636 Source: CCN Type: SECTRACK ID: 1014132 IBM AIX Buffer Overflows in invscout, paginit, diagTasksWebSM, getlvname, and swcons Commands and Multiple p Commands Let Local Users Execute Arbitrary Code Source: SECTRACK Type: UNKNOWN 1014132 Source: CCN Type: Computer Academic Underground Security Advisory CAU-2005-0006 IBM AIX p* Commandline Argument Overflow Source: MISC Type: Vendor Advisory http://www.caughq.org/advisories/CAU-2005-0006.txt Source: CONFIRM Type: Patch, Vendor Advisory http://www.security-focus.com/advisories/8684 Source: BID Type: Patch 13915 Source: CCN Type: BID-13915 IBM AIX Penable Command Line Argument Local Buffer Overflow Vulnerability Source: CCN Type: BID-13916 IBM AIX Pdisable Command Line Argument Local Buffer Overflow Vulnerability Source: CCN Type: BID-13917 IBM AIX Pstart Command Line Argument Local Buffer Overflow Vulnerability Source: CCN Type: BID-13918 IBM AIX Phold Command Line Argument Local Buffer Overflow Vulnerability Source: CCN Type: BID-13919 IBM AIX Pdelay Command Line Argument Local Buffer Overflow Vulnerability Source: CCN Type: BID-13920 IBM AIX Pshare Command Line Argument Local Buffer Overflow Vulnerability Source: XF Type: UNKNOWN aix-p-bo(20936) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |