CVE-2012-4833: Low severity IBM VIOS vulnerability
Published Oct 1, 2012
·Updated
fuser in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly restrict the -k option, which allows local users to kill arbitrary processes via a crafted command line.
Affected Software
3 affected components
IBM VIOS=2.2.1.4-fp-25_sp-02
IBM AIX=6.1
IBM AIX=7.1
Remediation
Event History
Oct 1, 2012
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4833?
CVE-2012-4833 has a medium severity rating due to allowing local users to terminate arbitrary processes.
2
How do I fix CVE-2012-4833?
To fix CVE-2012-4833, apply the latest patches or updates provided by IBM for affected versions of AIX and VIOS.
3
Who is affected by CVE-2012-4833?
CVE-2012-4833 affects local users of IBM AIX versions 6.1 and 7.1, as well as VIOS version 2.2.1.4-FP-25 SP-02.
4
What is the impact of CVE-2012-4833?
The impact of CVE-2012-4833 allows unauthorized local users to kill processes, potentially disrupting services.
5
Is there a workaround for CVE-2012-4833?
A potential workaround for CVE-2012-4833 is to restrict user access or privilege levels until a patch can be applied.