First published: Wed Aug 08 2007(Updated: )
AIX 5.2 and 5.3 install pioinit with user and group ownership of bin, which allows local users with bin or possibly printq privileges to gain root privileges by modifying pioinit.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM AIX | =5.3 | |
IBM AIX | =5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4238 is considered a high severity vulnerability due to its potential for local users to gain root privileges.
To fix CVE-2007-4238, ensure that the ownership and permissions of pioinit are correctly set to prevent unauthorized access.
CVE-2007-4238 affects IBM AIX versions 5.2 and 5.3.
Local users with bin or possibly printq privileges can exploit CVE-2007-4238 to gain root access.
A recommended workaround for CVE-2007-4238 is to restrict access to the pioinit file to limit its modification.