CVE-2007-4622: High severity IBM AIX vulnerability
Published Nov 5, 2007
·Updated
Integer underflow in the dnsnamefromtext function in (1) libdnsnonsecure.a and (2) libdnssecure.a in IBM AIX 5.2 allows local users to gain privileges via a crafted "-y" (TSIG key) command line argument to dig.
Affected Software
1 affected component
IBM AIX=5.2
Remediation
Patch Available
Patch Available
Event History
Nov 5, 2007
CVE Published
04:46 PM
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4622?
CVE-2007-4622 has been classified as a high severity vulnerability due to the potential for local privilege escalation.
2
How do I fix CVE-2007-4622?
To fix CVE-2007-4622, it is recommended to update IBM AIX to a version that addresses this integer underflow vulnerability.
3
Who is affected by CVE-2007-4622?
CVE-2007-4622 affects users of IBM AIX 5.2 that utilize the dig command with crafted TSIG key arguments.
4
What type of vulnerability is CVE-2007-4622?
CVE-2007-4622 is an integer underflow vulnerability that can lead to privilege escalation for local users.
5
Is CVE-2007-4622 exploitable remotely?
CVE-2007-4622 is not exploitable remotely as it requires local access to exploit.