CVE-2003-0784: Critical severity IBM AIX vulnerability
Format string vulnerability in tsm for the bos.rte.security fileset on AIX 5.2 allows remote attackers to gain root privileges via login, and local users to gain privileges via login, su, or passwd, with a username that contains format string specifiers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0784?
CVE-2003-0784 is considered critical due to the potential for remote attackers to gain root privileges.
How do I fix CVE-2003-0784?
To mitigate CVE-2003-0784, users should apply the latest patches provided by IBM for their AIX versions.
What systems are affected by CVE-2003-0784?
CVE-2003-0784 affects IBM AIX versions 4.3.3, 5.1, and 5.2.
Can local users exploit CVE-2003-0784?
Yes, local users can exploit CVE-2003-0784 to gain elevated privileges through specific username formats.
Is there a workaround for CVE-2003-0784 if I cannot apply the patch?
A temporary workaround for CVE-2003-0784 includes restricting user access and ensuring no usernames with format specifiers are created.