search menu icon-carat-right cmu-wordmark

CERT Coordination Center

IBM AIX enq buffer overflow in -M argument

Vulnerability Note VU#872257

Original Release Date: 2001-09-28 | Last Revised: 2001-09-28

Overview

There is a buffer overflow in the enq command that may allow a local attacker to gain root privileges.

Description

The enq command is used to add entries to a queue, usually for printing. There is a buffer overflow in the -M argument to the enq command.

Impact

An attacker with access to a local user account may be able to gain root privileges.

Solution

Apply a Patch

IBM has released patches to correct this problem. For AIX version 4.2, system adminstrators should apply APAR#IY08287. For AIX version 4.3, system administrators should apply APAR#IY08143. The patches for this problem also correct a vulnerability in the digest command.

Vendor Information


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

This document was written by Cory Cohen.

Other Information

CVE IDs: CVE-2000-1121
Severity Metric: 7.09
Date Public: 2000-12-01
Date First Published: 2001-09-28
Date Last Updated: 2001-09-28 16:02 UTC
Document Revision: 5

Sponsored by CISA.