Vulnerabilities > CVE-2007-4622 - Numeric Errors vulnerability in IBM AIX 5.2
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Integer underflow in the dns_name_fromtext function in (1) libdns_nonsecure.a and (2) libdns_secure.a in IBM AIX 5.2 allows local users to gain privileges via a crafted "-y" (TSIG key) command line argument to dig.
Common Weakness Enumeration (CWE)
Nessus
NASL family | AIX Local Security Checks |
NASL id | AIX_U812065.NASL |
description | The remote host is missing AIX PTF U812065, which is related to the security of the package bos.net.tcp.client. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 28980 |
published | 2007-12-03 |
reporter | This script is Copyright (C) 2007-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/28980 |
title | AIX 5.2 TL 10 : bos.net.tcp.client (U812065) |
code |
|
References
- ftp://aix.software.ibm.com/aix/efixes/security/dig_ifix.tar
- ftp://aix.software.ibm.com/aix/efixes/security/dig_ifix.tar
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=613
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=613
- http://secunia.com/advisories/27437
- http://secunia.com/advisories/27437
- http://securitytracker.com/id?1018871
- http://securitytracker.com/id?1018871
- http://www.ibm.com/support/docview.wss?uid=isg1IZ05017
- http://www.ibm.com/support/docview.wss?uid=isg1IZ05017
- http://www.securityfocus.com/bid/26262
- http://www.securityfocus.com/bid/26262
- http://www.vupen.com/english/advisories/2007/3669
- http://www.vupen.com/english/advisories/2007/3669
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38169
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38169