|
IBM AIX ftpd Two Vulnerabilities
|
|
Secunia Advisory:
|
SA23688
|
|
|
Release Date:
|
2007-01-09
|
|
Last Update:
|
2008-01-24
|
|
Popularity:
|
8,121 views
|
|
|
Critical:
|
 Moderately critical
|
|
Impact:
|
Exposure of sensitive information DoS
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| OS: | AIX 5.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2006-6914 CVE-2006-6915
|
|
Description: Two vulnerabilities have been reported in IBM AIX, which can potentially be exploited by malicious people to gain knowledge of sensitive information or to cause a DoS (Denial of Service).
The vulnerabilities are caused due to an unspecified error within bos.net.tcp.client. This can be exploited to crash the service or to disclose passwords.
Solution: Apply emergency fixes until APARs are available.
Emergency fix:
ftp://aix.software.ibm.com/aix/efixes/security/ftpd2_ifix.tar.Z
APAR for AIX 5.3.0:
Apply IY89168 (available)
APAR for AIX 5.2.0:
Apply IY91787 (available)
Provided and/or discovered by: Reported by the vendor.
Changelog: 2007-01-11: Added CVE reference.
2008-01-24: Updated "Solution" section (APAR IY91787 is available).
Original Advisory: http://www-1.ibm.com/support/docview.wss?uid=isg1IY89168
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|