CVE-2016-6079: High severity IBM AIX vulnerability
Published Feb 15, 2017
·Updated
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM APARs: IV88658, IV87981, IV88419, IV87640, IV88053.
Affected Software
43 affected components
IBM AIX=5.3
IBM AIX=6.1
IBM AIX=7.1
IBM AIX=7.2
IBM VIOS=2.2.0.0
IBM VIOS=2.2.0.10
IBM VIOS=2.2.0.11
IBM VIOS=2.2.0.12
IBM VIOS=2.2.0.13
IBM VIOS=2.2.1.0
IBM VIOS=2.2.1.1
IBM VIOS=2.2.1.3
IBM VIOS=2.2.1.4
IBM VIOS=2.2.1.5
IBM VIOS=2.2.1.6
IBM VIOS=2.2.1.7
IBM VIOS=2.2.1.8
IBM VIOS=2.2.2.0
IBM VIOS=2.2.2.1
IBM VIOS=2.2.2.2
IBM VIOS=2.2.2.3
IBM VIOS=2.2.2.4
IBM VIOS=2.2.2.6
IBM VIOS=2.2.2.70
IBM VIOS=2.2.3.0
IBM VIOS=2.2.3.1
IBM VIOS=2.2.3.2
IBM VIOS=2.2.3.3
IBM VIOS=2.2.3.4
IBM VIOS=2.2.3.50
IBM VIOS=2.2.3.51
IBM VIOS=2.2.3.52
IBM VIOS=2.2.3.60
IBM VIOS=2.2.3.70
IBM VIOS=2.2.3.80
IBM VIOS=2.2.4.0
IBM VIOS=2.2.4.10
IBM VIOS=2.2.4.21
IBM VIOS=2.2.4.22
IBM VIOS=2.2.4.23
IBM VIOS=2.2.4.30
IBM VIOS=2.2.5.0
IBM VIOS=2.2.5.10
Remediation
Event History
Feb 15, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Data Sourced
via NVD·07:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-6079?
CVE-2016-6079 has a high severity rating due to the potential for local users to gain root privileges.
2
How do I fix CVE-2016-6079?
To resolve CVE-2016-6079, apply the latest security updates and patches provided by IBM for affected AIX and VIOS versions.
3
Who is affected by CVE-2016-6079?
CVE-2016-6079 impacts users of IBM AIX versions 5.3, 6.1, 7.1, and 7.2, as well as certain versions of IBM VIOS.
4
What type of vulnerability is CVE-2016-6079?
CVE-2016-6079 is an unspecified local privilege escalation vulnerability.
5
Is there a workaround for CVE-2016-6079?
There are no recommended workarounds for CVE-2016-6079; updating to the fixed version is necessary.