First published: Mon Nov 05 2007(Updated: )
Integer underflow in the dns_name_fromtext function in (1) libdns_nonsecure.a and (2) libdns_secure.a in IBM AIX 5.2 allows local users to gain privileges via a crafted "-y" (TSIG key) command line argument to dig.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM AIX | =5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4622 has been classified as a high severity vulnerability due to the potential for local privilege escalation.
To fix CVE-2007-4622, it is recommended to update IBM AIX to a version that addresses this integer underflow vulnerability.
CVE-2007-4622 affects users of IBM AIX 5.2 that utilize the dig command with crafted TSIG key arguments.
CVE-2007-4622 is an integer underflow vulnerability that can lead to privilege escalation for local users.
CVE-2007-4622 is not exploitable remotely as it requires local access to exploit.