CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
COMPLETE
AV:L/AC:M/Au:N/C:N/I:N/A:C
AI Score
Confidence
Low
EPSS
Percentile
5.1%
The ptrace system call in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.x, allows local users to cause a denial of service (system crash) or obtain sensitive information from kernel memory via a crafted PT_LDINFO operation.
Vendor | Product | Version | CPE |
---|---|---|---|
ibm | vios | 2.2.0.10 | cpe:2.3:a:ibm:vios:2.2.0.10:*:*:*:*:*:*:* |
ibm | vios | 2.2.0.11 | cpe:2.3:a:ibm:vios:2.2.0.11:*:*:*:*:*:*:* |
ibm | vios | 2.2.0.12 | cpe:2.3:a:ibm:vios:2.2.0.12:*:*:*:*:*:*:* |
ibm | vios | 2.2.0.13 | cpe:2.3:a:ibm:vios:2.2.0.13:*:*:*:*:*:*:* |
ibm | vios | 2.2.1.0 | cpe:2.3:a:ibm:vios:2.2.1.0:*:*:*:*:*:*:* |
ibm | vios | 2.2.1.1 | cpe:2.3:a:ibm:vios:2.2.1.1:*:*:*:*:*:*:* |
ibm | vios | 2.2.1.3 | cpe:2.3:a:ibm:vios:2.2.1.3:*:*:*:*:*:*:* |
ibm | vios | 2.2.1.4 | cpe:2.3:a:ibm:vios:2.2.1.4:*:*:*:*:*:*:* |
ibm | vios | 2.2.2.0 | cpe:2.3:a:ibm:vios:2.2.2.0:*:*:*:*:*:*:* |
ibm | vios | 2.2.3.0 | cpe:2.3:a:ibm:vios:2.2.3.0:*:*:*:*:*:*:* |
aix.software.ibm.com/aix/efixes/security/ptrace_advisory.asc
archives.neohapsis.com/archives/bugtraq/2014-05/0031.html
www.ibm.com/support/docview.wss?uid=isg1IV58766
www.ibm.com/support/docview.wss?uid=isg1IV58840
www.ibm.com/support/docview.wss?uid=isg1IV58861
www.ibm.com/support/docview.wss?uid=isg1IV58888
www.ibm.com/support/docview.wss?uid=isg1IV58948
www.ibm.com/support/docview.wss?uid=isg1IV59045
www.ibm.com/support/docview.wss?uid=isg1IV59675
exchange.xforce.ibmcloud.com/vulnerabilities/92262
www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-0930/