First published: Tue Nov 14 2000(Updated: )
netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network interface statistics and possibly hide evidence of unusual network activities.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM AIX | =4.3.2 | |
IBM AIX | =4.3 | |
IBM AIX | =4.2.1 | |
IBM AIX | =4.2 | |
IBM AIX | =4.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0873 is classified as a moderate vulnerability due to its potential for local users to manipulate network interface statistics.
To mitigate CVE-2000-0873, restrict the use of the netstat -Zi option to authorized personnel or update to a patched version of AIX.
CVE-2000-0873 affects IBM AIX versions 4.2 and 4.3, including specific releases like 4.2.1, 4.3.1, and 4.3.2.
CVE-2000-0873 can enable local users to clear network statistics, which may obscure malicious activities or network anomalies.
CVE-2000-0873 can be exploited by local users who have access to the AIX system and can execute commands using the netstat utility.