Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-2669

Опубликовано: 05 авг. 2009
Источник: nvd
CVSS2: 7.2
EPSS Низкий

Описание

A certain debugging component in IBM AIX 5.3 and 6.1 does not properly handle the (1) _LIB_INIT_DBG and (2) _LIB_INIT_DBG_FILE environment variables, which allows local users to gain privileges by leveraging a setuid-root program to create an arbitrary root-owned file with world-writable permissions, related to libC.a (aka the XL C++ runtime library) in AIX 5.3 and libc.a in AIX 6.1.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:ibm:aix:5.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:6.1:*:*:*:*:*:*:*

EPSS

Процентиль: 23%
0.00077
Низкий

7.2 High

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
почти 4 года назад

A certain debugging component in IBM AIX 5.3 and 6.1 does not properly handle the (1) _LIB_INIT_DBG and (2) _LIB_INIT_DBG_FILE environment variables, which allows local users to gain privileges by leveraging a setuid-root program to create an arbitrary root-owned file with world-writable permissions, related to libC.a (aka the XL C++ runtime library) in AIX 5.3 and libc.a in AIX 6.1.

EPSS

Процентиль: 23%
0.00077
Низкий

7.2 High

CVSS2

Дефекты

CWE-264