Back to search
CVE-2012-0745
Published: May 4, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
The getpwnam function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.1.0.10 through 2.2.1.3 does not properly interact with customer-extended LDAP user filtering, which allows local users to gain privileges via unspecified vectors.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
1027021
vdb-entry
x_refsource_SECTRACK
IV19098
vendor-advisory
x_refsource_AIXAPAR
IV18637
vendor-advisory
x_refsource_AIXAPAR
49073
third-party-advisory
x_refsource_SECUNIA
aix-getpwnam-privilege-escalation(74679)
vdb-entry
x_refsource_XF
IV19077
vendor-advisory
x_refsource_AIXAPAR
IV19097
vendor-advisory
x_refsource_AIXAPAR
http://aix.software.ibm.com/aix/efixes/security/ldapauth_advisory2.asc
x_refsource_CONFIRM
IV18464
vendor-advisory
x_refsource_AIXAPAR
53393
vdb-entry
x_refsource_BID
IV18638
vendor-advisory
x_refsource_AIXAPAR
81683
vdb-entry
x_refsource_OSVDB
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now