IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: IV91006, IV91007, IV91008, IV91010, IV91011.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1037480 | vdb entry |
http://aix.software.ibm.com/aix/efixes/security/bellmail_advisory.asc | patch vendor advisory mitigation |
http://www.securityfocus.com/bid/94979 | vdb entry third party advisory |
https://www.exploit-db.com/exploits/40950/ | exploit |