CVE-2014-3074: High severity ibm virtual i/o server (vios) vulnerability
The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, by setting crafted MALLOCOPTIONS and MALLOCBUCKETS environment-variable values and then executing a setuid program.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3074?
CVE-2014-3074 is classified as a high-severity vulnerability due to its potential for local privilege escalation.
How do I fix CVE-2014-3074?
To fix CVE-2014-3074, update the affected IBM AIX or VIOS systems to the latest patches provided by IBM.
Which versions are affected by CVE-2014-3074?
CVE-2014-3074 affects IBM AIX 6.1, AIX 7.1, and various versions of IBM VIOS including 2.2.x and 2.2.1.x.
Can CVE-2014-3074 be exploited remotely?
CVE-2014-3074 cannot be exploited remotely as it requires local user access to execute a setuid program with specific environment variables.
What are the consequences of CVE-2014-3074 exploitation?
Exploitation of CVE-2014-3074 can lead to the creation of a root-owned file, allowing local users to gain elevated privileges on the system.