Overview
There is a buffer overflow in nslookup that will allow local attackers to gain root privileges on vulnerable AIX systems.
Description
The nslookup command contains a buffer overflow in the hostname to lookup, allowing local attackers to gain root privileges. The vendor (IBM) has reported publicly that this buffer overflow has been exploited by intruders to gain privileges. |
Impact
Intruders with access to a local account may be able to gain root privileges on the vulnerable system. |
Solution
Apply a Patch |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This document was written by Cory F. Cohen.
Other Information
CVE IDs: | None |
Severity Metric: | 15.75 |
Date Public: | 1999-09-30 |
Date First Published: | 2001-09-26 |
Date Last Updated: | 2001-09-26 18:04 UTC |
Document Revision: | 7 |