CVE Vulnerabilities

CVE-2009-2669

Published: Aug 05, 2009 | Modified: Aug 12, 2009
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

A certain debugging component in IBM AIX 5.3 and 6.1 does not properly handle the (1) _LIB_INIT_DBG and (2) _LIB_INIT_DBG_FILE environment variables, which allows local users to gain privileges by leveraging a setuid-root program to create an arbitrary root-owned file with world-writable permissions, related to libC.a (aka the XL C++ runtime library) in AIX 5.3 and libc.a in AIX 6.1.

Affected Software

Name Vendor Start Version End Version
Aix Ibm 5.3 (including) 5.3 (including)
Aix Ibm 6.1 (including) 6.1 (including)

References