Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, by setting crafted MALLOCOPTIONS and MALLOCBUCKETS environment-variable values and then executing a setuid program.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM AIX和VIOS 权限许可和访问控制问题漏洞
Vulnerability Description
IBM AIX(Advanced Interactive eXecutive)和VIOS都是美国IBM公司的产品。AIX是一套UNIX操作系统;VIOS是一款虚拟IO服务器。 IBM AIX 6.1和7.1版本和VIOS 2.2.x版本中的runtime linker存在安全漏洞。本地攻击者可通过设置特制的MALLOCOPTIONS和MALLOCBUCKETS环境变量值,并执行setuid程序利用该漏洞创建666权限的root所有文件,并获取提升的权限。
CVSS Information
N/A
Vulnerability Type
N/A