The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


Patches available for IBM AIX flaws


<< Previous INDEX Search src / Print Next >>
From: "NGSSoftware Insight Security Research" <nisr@nextgenss.com.>
To: <bugtraq@securityfocus.com.>, <dbsec@freelists.org.>
Subject: Patches available for IBM AIX flaws
Date: Thu, 15 Dec 2005 17:12:52 -0000
MIME-Version: 1.0
Content-Type: text/plain;
        format=flowed;
        charset="iso-8859-1";
        reply-type=original
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.2180
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
X-Virus-Scanned: antivirus-gw at tyumen.ru

David Litchfield of NGSSoftware has discovered a multiple high risk 
vulnerabilities in IBM's AIX operating systems.

1) There is a buffer overflow in the malloc debug system that when exploited 
can yeild root privileges.
2) There is a buffer overflow in muxatmd which is setuid root.
3) There is a buffer overflow in slocal which is setuid root.
4) There are arbitrary file data append issues in getShell and getCommand in 
conjuction with specific settings in the malloc debug system.Both getShell 
and getCommand are setuid root.

Issue 1 affects AIX versions 5.3.
Issue 2 affects AIX versions 5.3, 5.2 and 5.1.
Issue 3 affects AIX versions 5.3, 5.2 and 5.1.
Issue 4 affects AIX versions 5.3, 5.2 and 5.1.

IBM has developed patches for these issues:

http://www-03.ibm.com/servers/eserver/support/unixservers/aixfixes.html

Administrators are urged to install the patches as soon as possible. Whilst 
these attacks are "local" by nature, AIX servers running Informix, DB2 and 
Oracle can be targeted remotely via specific SQL queries.

NGSSoftware Insight Security Research
http://www.ngssoftware.com/
http://www.databasesecurity.com/
+44(0)208 401 0070






<< Previous INDEX Search src / Print Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2024 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру