CVE-2007-0670: Buffer Overflow
Published Feb 3, 2007
·Updated
Buffer overflow in bos.rte.libc in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code via the "r-commands", possibly including (1) rdist, (2) rsh, (3) rcp, (4) rsync, and (5) rlogin.
Affected Software
2 affected components
IBM AIX=5.3
IBM AIX=5.2
Event History
Feb 3, 2007
CVE Published
12:28 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0670?
CVE-2007-0670 is classified as a critical vulnerability due to its ability to allow local users to execute arbitrary code.
2
How do I fix CVE-2007-0670?
To fix CVE-2007-0670, apply the appropriate patches provided by IBM for AIX versions 5.2 and 5.3.
3
Who is affected by CVE-2007-0670?
CVE-2007-0670 affects local users of IBM AIX 5.2 and 5.3 systems.
4
What are the potential impacts of exploiting CVE-2007-0670?
Exploiting CVE-2007-0670 can lead to unauthorized execution of arbitrary code, compromising system integrity and confidentiality.
5
Is there a workaround for CVE-2007-0670 if patches cannot be applied immediately?
A temporary workaround for CVE-2007-0670 includes limiting local user access to sensitive commands that are vulnerable to exploitation.