The perfstat kernel extension in bos.perf.perfstat in AIX 5.3 does not verify privileges when processing a SET call, which allows local users to cause a denial of service (system hang or crash) via unspecified SET operations.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/26715 | third party advisory patch vendor advisory |
http://www.vupen.com/english/advisories/2007/3059 | vdb entry |
http://osvdb.org/40392 | vdb entry |
http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=3850 | patch |
http://www-1.ibm.com/support/docview.wss?uid=isg1IY97309 | patch vendor advisory |
http://www.securityfocus.com/bid/25554 | vdb entry patch |