Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Stack-based buffer overflow in the domacro function in ftp in IBM AIX 5.2 and 5.3 allows local users to gain privileges via a long parameter to a macro, as demonstrated by executing a macro via the '$' command.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM AIX ftp程序本地栈溢出漏洞
Vulnerability Description
IBM AIX是一款商业性质的UNIX操作系统。 AIX中所安装的FTP客户端的domacro()函数存在缓冲区溢出漏洞,本地攻击者可能利用此漏洞提升权限。 在通过FTP程序的"$"命令执行宏的时候会调用这个函数。在执行宏的时候,未经边界限制便使用strcpy()调用将参数拷贝到了固定大小的栈缓冲区,如果攻击者指定了超长参数的话,就可能覆盖栈上的程序控制数据,获得对受影响进程的完全控制。
CVSS Information
N/A
Vulnerability Type
N/A