IBM Support

IY55681: SECURITY: POSSIBLE BUFFER OVERFLOW IN PUTLVCB COMMAND

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • A possible buffer overflow in the putlvcb command could
    allow a local user to obtain root priviledges.
    

Local fix

Problem summary

  • A possible buffer overflow in the putlvcb command could
    allow a local user to obtain root priviledges.
    

Problem conclusion

  • Additional checks were added to avert buffer overflow.
    

Temporary fix

Comments

APAR Information

  • APAR number

    IY55681

  • Reported component name

    AIX 5L FOR POWE

  • Reported component ID

    5765E6100

  • Reported release

    510

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Submitted date

    2004-04-12

  • Closed date

    2004-04-22

  • Last modified date

    2004-05-28

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    IY55682

Fix information

  • Fixed component name

    AIX 5L FOR POWE

  • Fixed component ID

    5765E6100

Applicable component levels

  • R510 PSY U487216

       UP04/05/28 I 1000

[{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SG11N","label":"APARs - AIX 5.1 environment"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"510","Edition":"","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
28 May 2004