CVE-2000-0249: High severity IBM AIX vulnerability

Published Apr 26, 2000
·
Updated

The AIX Fast Response Cache Accelerator (FRCA) allows local users to modify arbitrary files via the configuration capability in the frcactrl program.

Affected Software

3 affected components
IBM AIX=4.3.2
IBM AIX=4.3
IBM AIX=4.3.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove IBM AIX Fast Response Cache Accelerator (FRCA) from your environment.

    Uninstall or disable the AIX Fast Response Cache Accelerator (FRCA) if it is not required, and remove or disable the frcactrl program.

  2. Configuration

    Restrict access to the frcactrl program so only root/administrators can run it and modify its configuration (e.g., change ownership to an administrative account and remove execute/write permissions for non-privileged users or apply appropriate filesystem ACLs).

    frcactrl executable/configuration access = administrators only
  3. Compensating control

    Limit local user privileges and access to system files (apply least-privilege, restrict local logins, and enforce filesystem ACLs) to reduce the ability of local users to modify arbitrary files via frcactrl.

  4. Operational

    Audit systems for unauthorized changes to files and configurations made via frcactrl, restore modified files from trusted backups if needed, and rotate any credentials or keys that may have been exposed.

Event History

Apr 26, 2000
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Jul 12, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2000-0249?

CVE-2000-0249 is considered a moderate severity vulnerability that allows local users to modify arbitrary files.

2

How do I fix CVE-2000-0249?

To fix CVE-2000-0249, update the AIX Fast Response Cache Accelerator to a version that addresses this vulnerability.

3

Who is affected by CVE-2000-0249?

CVE-2000-0249 affects local users on IBM AIX versions 4.3.1 and 4.3.2.

4

What is the impact of CVE-2000-0249?

The impact of CVE-2000-0249 is that local users can gain unauthorized access to modify system files.

5

Is CVE-2000-0249 still a concern today?

While CVE-2000-0249 is an older vulnerability, it remains a concern for organizations using affected versions of AIX.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203