Vulnerability Name: | CVE-2010-3405 (CCN-61774) | ||||||||
Assigned: | 2010-09-13 | ||||||||
Published: | 2010-09-13 | ||||||||
Updated: | 2018-11-28 | ||||||||
Summary: | Buffer overflow in sa_snap in the bos.esagent fileset in IBM AIX 6.1, 5.3, and earlier and VIOS 2.1, 1.5, and earlier allows local users to leverage system group membership and gain privileges via unspecified vectors. | ||||||||
CVSS v3 Severity: | 4.8 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C) 5.0 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-119 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: IBM SECURITY ADVISORY AIX security vulnerabilities in sa_snap Source: CONFIRM Type: Patch, Vendor Advisory http://aix.software.ibm.com/aix/efixes/security/sa_snap_advisory.asc Source: MITRE Type: CNA CVE-2010-3405 Source: CCN Type: SA41446 IBM AIX sa_snap Two Vulnerabilities Source: SECUNIA Type: Third Party Advisory 41446 Source: CCN Type: SECTRACK ID: 1024430 IBM AIX Buffer Overflow in sa_snap Lets Local Users Gain Elevated Privileges Source: SECTRACK Type: Third Party Advisory, VDB Entry 1024430 Source: AIXAPAR Type: Vendor Advisory IZ81819 Source: AIXAPAR Type: Vendor Advisory IZ82245 Source: AIXAPAR Type: Vendor Advisory IZ82630 Source: AIXAPAR Type: Vendor Advisory IZ83909 Source: AIXAPAR Type: Vendor Advisory IZ83942 Source: AIXAPAR Type: Vendor Advisory IZ83975 Source: AIXAPAR Type: Vendor Advisory IZ84167 Source: CCN Type: OSVDB ID: 68099 IBM AIX bos.esagent Fileset sa_snap Local Overflow Source: BID Type: Third Party Advisory, VDB Entry 43207 Source: CCN Type: BID-43207 IBM AIX Local Privilege Escalation and Security Bypass Vulnerabilities Source: VUPEN Type: Third Party Advisory ADV-2010-2377 Source: XF Type: Third Party Advisory, VDB Entry ibm-aix-sasnap-bo(61774) Source: XF Type: UNKNOWN ibm-aix-sasnap-bo(61774) Source: OVAL Type: Third Party Advisory oval:org.mitre.oval:def:12214 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |