The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, by setting crafted MALLOCOPTIONS and MALLOCBUCKETS environment-variable values and then executing a setuid program.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2014-07-02 03:35
Updated : 2021-08-31 08:44
NVD link : CVE-2014-3074
Mitre link : CVE-2014-3074
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
ibm
- aix
- vios