Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2014-3074

The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, by setting crafted MALLOCOPTIONS and MALLOCBUCKETS environment-variable values and then executing a setuid program.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 24.9%
CVSS Severity
CVSS v2 Score 7.2
References
Products affected by CVE-2014-3074
  • Ibm » Vios » Version: 2.2.0.10
    cpe:2.3:a:ibm:vios:2.2.0.10
  • Ibm » Vios » Version: 2.2.0.11
    cpe:2.3:a:ibm:vios:2.2.0.11
  • Ibm » Vios » Version: 2.2.0.12
    cpe:2.3:a:ibm:vios:2.2.0.12
  • Ibm » Vios » Version: 2.2.0.13
    cpe:2.3:a:ibm:vios:2.2.0.13
  • Ibm » Vios » Version: 2.2.1.0
    cpe:2.3:a:ibm:vios:2.2.1.0
  • Ibm » Vios » Version: 2.2.1.1
    cpe:2.3:a:ibm:vios:2.2.1.1
  • Ibm » Vios » Version: 2.2.1.3
    cpe:2.3:a:ibm:vios:2.2.1.3
  • Ibm » Vios » Version: 2.2.1.4
    cpe:2.3:a:ibm:vios:2.2.1.4
  • Ibm » Vios » Version: 2.2.1.8
    cpe:2.3:a:ibm:vios:2.2.1.8
  • Ibm » Vios » Version: 2.2.1.9
    cpe:2.3:a:ibm:vios:2.2.1.9
  • Ibm » Vios » Version: 2.2.2.0
    cpe:2.3:a:ibm:vios:2.2.2.0
  • Ibm » Vios » Version: 2.2.2.4
    cpe:2.3:a:ibm:vios:2.2.2.4
  • Ibm » Vios » Version: 2.2.2.5
    cpe:2.3:a:ibm:vios:2.2.2.5
  • Ibm » Vios » Version: 2.2.3.0
    cpe:2.3:a:ibm:vios:2.2.3.0
  • Ibm » Vios » Version: 2.2.3.2
    cpe:2.3:a:ibm:vios:2.2.3.2
  • Ibm » Vios » Version: 2.2.3.3
    cpe:2.3:a:ibm:vios:2.2.3.3
  • Ibm » Aix » Version: 6.1
    cpe:2.3:o:ibm:aix:6.1
  • Ibm » Aix » Version: 7.1
    cpe:2.3:o:ibm:aix:7.1


Contact Us

Shodan ® - All rights reserved