CVE-2000-1122: Buffer Overflow
Published Jan 9, 2001
·Updated
Buffer overflow in setclock command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long argument.
Affected Software
6 affected components
IBM AIX=4.3.2
IBM AIX=4.3
IBM AIX=4.2.1
IBM AIX=4.2
IBM AIX=4.3.3
IBM AIX=4.3.1
Remediation
Patch Available
Event History
Jan 9, 2001
CVE Published
05:00 AM
May 7, 2001
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-1122?
CVE-2000-1122 is classified as a medium severity vulnerability due to the potential for local users to execute arbitrary commands.
2
How do I fix CVE-2000-1122?
To remediate CVE-2000-1122, upgrade to a version of IBM AIX that does not include the vulnerable setclock command, specifically versions later than AIX 4.3.3.
3
Who is affected by CVE-2000-1122?
Local users of IBM AIX versions 4.2.x and 4.3.x are affected by CVE-2000-1122.
4
What type of attack can exploit CVE-2000-1122?
CVE-2000-1122 can be exploited through a local buffer overflow attack, allowing execution of arbitrary commands.
5
Is CVE-2000-1122 a local or remote vulnerability?
CVE-2000-1122 is considered a local vulnerability as it can only be exploited by local users with access to the system.