fuser in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly restrict the -k option, which allows local users to kill arbitrary processes via a crafted command line.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/78907 | vdb entry |
http://www.ibm.com/support/docview.wss?uid=isg1IV28756 | vendor advisory |
http://www.ibm.com/support/docview.wss?uid=isg1IV28754 | vendor advisory |
http://aix.software.ibm.com/aix/efixes/security/fuser_advisory.asc | patch vendor advisory |
http://www.ibm.com/support/docview.wss?uid=isg1IV28151 | vendor advisory |
http://secunia.com/advisories/50708 | third party advisory |
http://www.securityfocus.com/bid/55726 | vdb entry |
http://www.securitytracker.com/id?1027586 | vdb entry |
http://www.ibm.com/support/docview.wss?uid=isg1IV28749 | vendor advisory |