CVE-2006-1246: High severity IBM AIX vulnerability
Published Mar 17, 2006
·Updated
Unspecified vulnerability in mklvcopy in BOS.RTE.LVM in IBM AIX 5.3 allows local users to execute arbitrary commands when mklvcopy calls external commands, possibly due to an untrusted search path vulnerability.
Affected Software
1 affected component
IBM AIX=5.3
Remediation
Patch Available
Patch Available
Event History
Mar 17, 2006
CVE Published
11:02 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1246?
CVE-2006-1246 is classified as a medium severity vulnerability.
2
How do I fix CVE-2006-1246?
To fix CVE-2006-1246, update your IBM AIX system to the latest version that addresses this vulnerability.
3
What is the impact of CVE-2006-1246?
The impact of CVE-2006-1246 allows local users to execute arbitrary commands due to an untrusted search path in mklvcopy.
4
Is there a workaround for CVE-2006-1246?
A practical workaround for CVE-2006-1246 is to limit local user access or restrict the execution of the mklvcopy command.
5
Who is affected by CVE-2006-1246?
Users running IBM AIX 5.3 are affected by CVE-2006-1246.