CVE-2000-0249: High severity IBM AIX vulnerability
The AIX Fast Response Cache Accelerator (FRCA) allows local users to modify arbitrary files via the configuration capability in the frcactrl program.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
IBM AIX Fast Response Cache Accelerator (FRCA)from your environment.Uninstall or disable the AIX Fast Response Cache Accelerator (FRCA) if it is not required, and remove or disable the frcactrl program.
- Configuration
Restrict access to the frcactrl program so only root/administrators can run it and modify its configuration (e.g., change ownership to an administrative account and remove execute/write permissions for non-privileged users or apply appropriate filesystem ACLs).
frcactrl executable/configuration access = administrators only - Compensating control
Limit local user privileges and access to system files (apply least-privilege, restrict local logins, and enforce filesystem ACLs) to reduce the ability of local users to modify arbitrary files via frcactrl.
- Operational
Audit systems for unauthorized changes to files and configurations made via frcactrl, restore modified files from trusted backups if needed, and rotate any credentials or keys that may have been exposed.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0249?
CVE-2000-0249 is considered a moderate severity vulnerability that allows local users to modify arbitrary files.
How do I fix CVE-2000-0249?
To fix CVE-2000-0249, update the AIX Fast Response Cache Accelerator to a version that addresses this vulnerability.
Who is affected by CVE-2000-0249?
CVE-2000-0249 affects local users on IBM AIX versions 4.3.1 and 4.3.2.
What is the impact of CVE-2000-0249?
The impact of CVE-2000-0249 is that local users can gain unauthorized access to modify system files.
Is CVE-2000-0249 still a concern today?
While CVE-2000-0249 is an older vulnerability, it remains a concern for organizations using affected versions of AIX.