First published: Thu May 08 2014(Updated: )
The ptrace system call in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.x, allows local users to cause a denial of service (system crash) or obtain sensitive information from kernel memory via a crafted PT_LDINFO operation.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Virtual I/O Server (VIOS) | =2.2.0.10 | |
IBM Virtual I/O Server (VIOS) | =2.2.0.11 | |
IBM Virtual I/O Server (VIOS) | =2.2.0.12 | |
IBM Virtual I/O Server (VIOS) | =2.2.0.13 | |
IBM Virtual I/O Server (VIOS) | =2.2.1.0 | |
IBM Virtual I/O Server (VIOS) | =2.2.1.1 | |
IBM Virtual I/O Server (VIOS) | =2.2.1.3 | |
IBM Virtual I/O Server (VIOS) | =2.2.1.4 | |
IBM Virtual I/O Server (VIOS) | =2.2.2.0 | |
IBM Virtual I/O Server (VIOS) | =2.2.3.0 | |
IBM AIX | =5.3 | |
IBM AIX | =6.1 | |
IBM AIX | =7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0930 is categorized as a moderate severity vulnerability, allowing local users to cause a denial of service or access sensitive kernel memory.
To fix CVE-2014-0930, apply the latest patches or updates provided by IBM for affected AIX and VIOS versions.
CVE-2014-0930 affects IBM AIX versions 5.3, 6.1, 7.1 and VIOS versions 2.2.0.10 to 2.2.3.0.
CVE-2014-0930 can result in a system crash or unauthorized access to sensitive information in the kernel memory.
CVE-2014-0930 is a local vulnerability that can only be exploited by users with local access to the system.