Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
AIX 5.1/5.2/5.3 local root exploits Dec 20 2004 11:10AM
cees-bart (ceesb cs ru nl)
hi,

i found some local security holes in IBM's AIX versions 5.1, 5.2 and 5.3
(unix for IBM RS/6000 powerpc).

1) the first is a bug in all setuid diag related tools that use an
environment variable as a prefix to an external binary executed as root.

2) the second is a classical stack overflow in...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus