CVE-2006-5007: Medium severity IBM AIX vulnerability
Published Sep 27, 2006
·Updated
Untrusted search path vulnerability in uucp in IBM AIX 5.2.0 and 5.3.0 allows local users to local users to gain privileges via a Trojan horse program involving uux.
Affected Software
2 affected components
IBM AIX=5.2.0
IBM AIX=5.3.0
Remediation
Patch Available
Patch Available
Event History
Sep 27, 2006
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·01:07 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2006-5007?
CVE-2006-5007 is considered to have a high severity due to the potential for local users to gain elevated privileges.
2
How do I fix CVE-2006-5007?
To fix CVE-2006-5007, ensure that you apply the relevant patches provided by IBM for AIX versions 5.2.0 and 5.3.0.
3
What systems are affected by CVE-2006-5007?
CVE-2006-5007 affects IBM AIX versions 5.2.0 and 5.3.0.
4
Can CVE-2006-5007 be exploited remotely?
No, CVE-2006-5007 requires local access to the system to exploit the vulnerability.
5
Is there a workaround for CVE-2006-5007?
A possible workaround for CVE-2006-5007 is to restrict access to the uucp and uux commands to trusted users only.