Vulnerabilities > CVE-2006-5007 - Local Privilege Escalation vulnerability in IBM AIX 5.2.0/5.3.0

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
ibm
nessus

Summary

Untrusted search path vulnerability in uucp in IBM AIX 5.2.0 and 5.3.0 allows local users to local users to gain privileges via a Trojan horse program involving uux.

Vulnerable Configurations

Part Description Count
OS
Ibm
2

Nessus

  • NASL familyAIX Local Security Checks
    NASL idAIX_U808255.NASL
    descriptionThe remote host is missing AIX PTF U808255, which is related to the security of the package bos.net.uucp.
    last seen2020-06-01
    modified2020-06-02
    plugin id65303
    published2013-03-13
    reporterThis script is Copyright (C) 2013-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/65303
    titleAIX 5.2 TL 9 / 5.2 TL 10 : bos.net.uucp (U808255)
    code
    #%NASL_MIN_LEVEL 80502
    #
    # (C) Tenable Network Security, Inc.
    #
    # The descriptive text and package checks in this plugin were extracted
    # from AIX Security PTF U808255. The text itself is copyright (C)
    # International Business Machines Corp.
    #
    
    include("compat.inc");
    
    if (description)
    {
      script_id(65303);
      script_version("1.2");
      script_cvs_date("Date: 2019/09/16 14:12:47");
    
      script_cve_id("CVE-2006-5007");
    
      script_name(english:"AIX 5.2 TL 9 / 5.2 TL 10 : bos.net.uucp (U808255)");
      script_summary(english:"Check for PTF U808255");
    
      script_set_attribute(
        attribute:"synopsis", 
        value:"The remote AIX host is missing a vendor-supplied security patch."
      );
      script_set_attribute(
        attribute:"description", 
        value:
    "The remote host is missing AIX PTF U808255, which is related to the
    security of the package bos.net.uucp."
      );
      script_set_attribute(
        attribute:"see_also",
        value:"http://www-01.ibm.com/support/docview.wss?uid=isg1IY88565"
      );
      script_set_attribute(
        attribute:"see_also",
        value:"http://www-01.ibm.com/support/docview.wss?uid=isg1IY88568"
      );
      script_set_attribute(
        attribute:"solution", 
        value:"Install the appropriate missing security-related fix."
      );
      script_set_cvss_base_vector("CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P");
    
      script_set_attribute(attribute:"plugin_type", value:"local");
      script_set_attribute(attribute:"cpe", value:"cpe:/o:ibm:aix:5.2");
    
      script_set_attribute(attribute:"vuln_publication_date", value:"2006/08/17");
      script_set_attribute(attribute:"patch_publication_date", value:"2006/08/17");
      script_set_attribute(attribute:"plugin_publication_date", value:"2013/03/13");
      script_end_attributes();
    
      script_category(ACT_GATHER_INFO);
      script_copyright(english:"This script is Copyright (C) 2013-2019 Tenable Network Security, Inc.");
      script_family(english:"AIX Local Security Checks");
    
      script_dependencies("ssh_get_info.nasl");
      script_require_keys("Host/local_checks_enabled", "Host/AIX/oslevel", "Host/AIX/version", "Host/AIX/lslpp");
    
      exit(0);
    }
    
    
    
    include("audit.inc");
    include("global_settings.inc");
    include("aix.inc");
    
    if ( ! get_kb_item("Host/local_checks_enabled") ) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED);
    if ( ! get_kb_item("Host/AIX/version") ) audit(AUDIT_OS_NOT, "AIX");
    if ( ! get_kb_item("Host/AIX/lslpp") ) audit(AUDIT_PACKAGE_LIST_MISSING);
    
    flag = 0;
    
    if ( aix_check_patch(ml:"520009", patch:"U808255", package:"bos.net.uucp.5.2.0.96") < 0 ) flag++;
    if ( aix_check_patch(ml:"520010", patch:"U808255", package:"bos.net.uucp.5.2.0.96") < 0 ) flag++;
    
    if (flag)
    {
      if (report_verbosity > 0) security_warning(port:0, extra:aix_report_get());
      else security_warning(0);
      exit(0);
    }
    else audit(AUDIT_HOST_NOT, "affected");
    
  • NASL familyAIX Local Security Checks
    NASL idAIX_U807064.NASL
    descriptionThe remote host is missing AIX PTF U807064, which is related to the security of the package bos.net.uucp.
    last seen2020-06-01
    modified2020-06-02
    plugin id65294
    published2013-03-13
    reporterThis script is Copyright (C) 2013-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/65294
    titleAIX 5.3 TL 5 / 5.3 TL 6 : bos.net.uucp (U807064)