CVE-2016-6079
high
CVSS v3
7.8
CVSS v2
7.2
VIR risk
7.8
Description
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM APARs: IV88658, IV87981, IV88419, IV87640, IV88053.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — http://aix.software.ibm.com/aix/efixes/security/lquerylv_advisory.asc
Exploits
Exploit-DB
- EDB-40710 · local · aix
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ibm | vios | 2.2.0.0 | |
| ibm | vios | 2.2.0.10 | |
| ibm | vios | 2.2.0.11 | |
| ibm | vios | 2.2.0.12 | |
| ibm | vios | 2.2.0.13 | |
| ibm | vios | 2.2.1.0 | |
| ibm | vios | 2.2.1.1 | |
| ibm | vios | 2.2.1.3 | |
| ibm | vios | 2.2.1.4 | |
| ibm | vios | 2.2.1.5 | |
| ibm | vios | 2.2.1.6 | |
| ibm | vios | 2.2.1.7 | |
| ibm | vios | 2.2.1.8 | |
| ibm | vios | 2.2.2.0 | |
| ibm | vios | 2.2.2.1 | |
| ibm | vios | 2.2.2.2 | |
| ibm | vios | 2.2.2.3 | |
| ibm | vios | 2.2.2.4 | |
| ibm | vios | 2.2.2.6 | |
| ibm | vios | 2.2.2.70 | |
| ibm | vios | 2.2.3.0 | |
| ibm | vios | 2.2.3.1 | |
| ibm | vios | 2.2.3.2 | |
| ibm | vios | 2.2.3.3 | |
| ibm | vios | 2.2.3.4 | |
| ibm | vios | 2.2.3.50 | |
| ibm | vios | 2.2.3.51 | |
| ibm | vios | 2.2.3.52 | |
| ibm | vios | 2.2.3.60 | |
| ibm | vios | 2.2.3.70 | |
| ibm | vios | 2.2.3.80 | |
| ibm | vios | 2.2.4.0 | |
| ibm | vios | 2.2.4.10 | |
| ibm | vios | 2.2.4.21 | |
| ibm | vios | 2.2.4.22 | |
| ibm | vios | 2.2.4.23 | |
| ibm | vios | 2.2.4.30 | |
| ibm | vios | 2.2.5.0 | |
| ibm | vios | 2.2.5.10 | |
References
- http://aix.software.ibm.com/aix/efixes/security/lquerylv_advisory.asc
- http://www.securityfocus.com/bid/94090
- http://www.securitytracker.com/id/1037256
- https://www.exploit-db.com/exploits/40710/
- http://aix.software.ibm.com/aix/efixes/security/lquerylv_advisory.asc
- http://www.securityfocus.com/bid/94090
- http://www.securitytracker.com/id/1037256
- https://www.exploit-db.com/exploits/40710/
CWEs
CWE-264
Verify integrity in audit chain (admin only). AS-IS.