CVE-2012-2200: High severity ibm virtual i/o server (vios) vulnerability
The default configuration of sendmail in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, allows local users to gain privileges by entering a command in a .forward file in a home directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2200?
CVE-2012-2200 is classified as a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2012-2200?
To mitigate CVE-2012-2200, users should change the default configuration of sendmail to disallow executing commands placed in .forward files.
Who is affected by CVE-2012-2200?
CVE-2012-2200 affects users of IBM AIX versions 6.1, 7.1, and IBM VIOS 2.2.1.4-FP-25 SP-02.
What type of attack does CVE-2012-2200 facilitate?
CVE-2012-2200 facilitates local privilege escalation attacks by allowing unprivileged users to execute arbitrary commands.
Is there a workaround for CVE-2012-2200?
A temporary workaround for CVE-2012-2200 is to disable processing of the .forward file to prevent unauthorized command execution.