CVE-2008-1599: High severity ibm aix vulnerability
Published Mar 31, 2008
·Updated
The nddstat programs on IBM AIX 5.2, 5.3, and 6.1 do not properly handle environment variables, which allows local users to gain privileges by invoking (1) atmstat, (2) entstat, (3) fddistat, (4) hdlcstat, or (5) tokstat.
Affected Software
3 affected components
IBM AIX=5.3
IBM AIX=5.2
IBM AIX=6.1
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Mar 31, 2008
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1599?
CVE-2008-1599 has a medium severity rating, indicating a potential for local privilege escalation.
2
How do I fix CVE-2008-1599?
To fix CVE-2008-1599, update your IBM AIX system to the latest version that addresses this vulnerability.
3
Which versions of IBM AIX are affected by CVE-2008-1599?
CVE-2008-1599 affects IBM AIX versions 5.2, 5.3, and 6.1.
4
What types of programs are involved in CVE-2008-1599?
The programs involved in CVE-2008-1599 include atmstat, entstat, fddistat, hdlcstat, and tokstat.
5
Can local users exploit CVE-2008-1599?
Yes, local users can gain elevated privileges on systems affected by CVE-2008-1599 through improper handling of environment variables.