![]() |
with SecurityTracker! | |
Home | View Topics | Search | |
|
Category: Application (Generic) > Perl | Vendors: IBM |
Perl on IBM AIX Lets Local Users Gain Elevated Privileges
|
SecurityTracker Alert ID: 1018177 |
SecurityTracker URL: https://securitytracker.com/id/1018177 |
CVE Reference: CVE-2007-2996 (Links to External Site) |
Updated: May 12 2008 |
Original Entry Date: May 31 2007
|
Impact:
User access via local system |
Fix Available: Yes Vendor Confirmed: Yes |
|
Description:
A vulnerability was reported in Perl on IBM AIX. A local user can obtain elevated privileges on the target system. A local user can cause arbitrary code to be executed on the target system when the target user executes a binary that ships with Perl. The code will run with the privileges of the target user. |
Impact:
A local user can obtain elevated privileges on the target system. |
Solution:
IBM is developing the following fixes: APAR number for AIX 5.2.0: IY98394 (available approx. 07/25/07) APAR number for AIX 5.3.0: IY98395 (available approx. 07/04/07) Interim fixes are available at: ftp://aix.software.ibm.com/aix/efixes/security/perl_ifix.tar.Z |
Vendor URL: www.ibm.com/ (Links to External Site)
|
Cause:
Not specified |
Underlying OS: UNIX (AIX) |
Underlying OS Comments: 5.2, 5.3 |
|
Message History:
None.
|
![]() |
|