Lucene search

K
cve[email protected]CVE-2007-4622
HistoryNov 05, 2007 - 4:46 p.m.

CVE-2007-4622

2007-11-0516:46:00
CWE-189
web.nvd.nist.gov
22
ibm
aix
security vulnerability
integer underflow
local privilege escalation
dig
libdns_nonsecure.a
libdns_secure.a

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.4 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

Integer underflow in the dns_name_fromtext function in (1) libdns_nonsecure.a and (2) libdns_secure.a in IBM AIX 5.2 allows local users to gain privileges via a crafted “-y” (TSIG key) command line argument to dig.

Affected configurations

NVD
Node
ibmaixMatch5.2
CPENameOperatorVersion
ibm:aixibm aixeq5.2

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.4 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%