7.2
CVSSv2

CVE-2014-3074

Published: 02/07/2014 Updated: 31/08/2021
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, by setting crafted MALLOCOPTIONS and MALLOCBUCKETS environment-variable values and then executing a setuid program.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ibm vios 2.2.0.12

ibm vios 2.2.0.13

ibm vios 2.2.1.9

ibm vios 2.2.2.0

ibm vios 2.2.1.3

ibm vios 2.2.1.4

ibm vios 2.2.3.2

ibm vios 2.2.3.3

ibm vios 2.2.1.0

ibm vios 2.2.1.1

ibm vios 2.2.2.4

ibm vios 2.2.2.5

ibm vios 2.2.3.0

ibm vios 2.2.0.10

ibm vios 2.2.0.11

ibm vios 2.2.1.8

ibm aix 7.1

ibm aix 6.1

Exploits

This exploit takes advantage of known issues with debugging functions within the AIX linker library It takes advantage of known functionality, and focuses on badly coded SUID binaries which do not adhere to proper security checks prior to seteuid/open/writes ...