Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2009-2669

A certain debugging component in IBM AIX 5.3 and 6.1 does not properly handle the (1) _LIB_INIT_DBG and (2) _LIB_INIT_DBG_FILE environment variables, which allows local users to gain privileges by leveraging a setuid-root program to create an arbitrary root-owned file with world-writable permissions, related to libC.a (aka the XL C++ runtime library) in AIX 5.3 and libc.a in AIX 6.1.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 23.9%
CVSS Severity
CVSS v2 Score 7.2
References
Products affected by CVE-2009-2669
  • Ibm » Aix » Version: 5.3
    cpe:2.3:o:ibm:aix:5.3
  • Ibm » Aix » Version: 6.1
    cpe:2.3:o:ibm:aix:6.1


Contact Us

Shodan ® - All rights reserved