CVE-2009-0370: High severity IBM AIX vulnerability
Published Jan 30, 2009
·Updated
Multiple unspecified vulnerabilities in IBM AIX 5.2.0 through 6.1.2 allow local users to append data to arbitrary files, related to (1) rmsock and (2) rmsock64 not creating "secure log files."
Affected Software
11 affected components
IBM AIX=5.3.8
IBM AIX=5.3.7
IBM AIX=5.3_l
IBM AIX=5.3
IBM AIX=5.2
IBM AIX=6.1.1
IBM AIX=5.2_l
IBM AIX=6.1
IBM AIX=5.3.9
IBM AIX=5.2.2
IBM AIX=6.1.2
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Jan 30, 2009
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:30 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-0370?
CVE-2009-0370 has a moderate severity level due to the potential for local users to append data to arbitrary files.
2
How do I fix CVE-2009-0370?
To fix CVE-2009-0370, it is recommended to update to the latest patches provided by IBM for affected AIX versions.
3
Which versions of IBM AIX are affected by CVE-2009-0370?
CVE-2009-0370 affects IBM AIX versions from 5.2.0 through 6.1.2.
4
What are the implications of CVE-2009-0370 for local users?
Local users can exploit CVE-2009-0370 to manipulate log files, potentially compromising system integrity.
5
Is CVE-2009-0370 addressed by IBM support?
Yes, IBM has addressed CVE-2009-0370 and recommends specific updates to mitigate the vulnerabilities.