First published: Tue May 30 2006(Updated: )
Untrusted search path vulnerability in update_flash for IBM AIX 5.1, 5.2 and 5.3 allows local users to execute arbitrary commands via unknown vectors involving lsmcode and possibly other commands.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM AIX | =5.3 | |
IBM AIX | =5.2 | |
IBM AIX | =5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2647 is considered a medium to high severity vulnerability due to potential arbitrary command execution by local users.
To fix CVE-2006-2647, ensure that you apply the latest patches provided by IBM for AIX versions 5.1, 5.2, and 5.3.
CVE-2006-2647 affects local users of IBM AIX 5.1, 5.2, and 5.3 installations.
CVE-2006-2647 allows local users to execute arbitrary commands, potentially compromising the system.
Although it is an older vulnerability, systems still running affected versions of AIX without patches may be at risk.