VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-3405
aix, vios: Buffer overflow in sa_snap in the bos.esagent files...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-3405

Original

Buffer overflow in sa_snap in the bos.esagent fileset in IBM AIX 6.1, 5.3, and earlier and VIOS 2.1, 1.5, and earlier allows local users to leverage system group membership and gain privileges via unspecified vectors.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-09-16
Source Information Category:
Advisory, Alert
Last Updated:
2010-09-17




Affected Product Tags
cpe:/a:ibm:vios:1.1
cpe:/a:ibm:vios:1.4
cpe:/a:ibm:vios:1.5 and previous versions
cpe:/a:ibm:vios:2.0
cpe:/a:ibm:vios:2.1 and previous versions
cpe:/o:ibm:aix:1.2.1
cpe:/o:ibm:aix:1.3
cpe:/o:ibm:aix:2.2.1
cpe:/o:ibm:aix:3.1
cpe:/o:ibm:aix:3.2
cpe:/o:ibm:aix:3.2.0
cpe:/o:ibm:aix:3.2.4
cpe:/o:ibm:aix:3.2.5
cpe:/o:ibm:aix:4
cpe:/o:ibm:aix:4.0
cpe:/o:ibm:aix:4.1
cpe:/o:ibm:aix:4.1.1
cpe:/o:ibm:aix:4.1.2
cpe:/o:ibm:aix:4.1.3
cpe:/o:ibm:aix:4.1.4
cpe:/o:ibm:aix:4.1.5
cpe:/o:ibm:aix:4.2
cpe:/o:ibm:aix:4.2.0
cpe:/o:ibm:aix:4.2.1
cpe:/o:ibm:aix:4.2.1.12
cpe:/o:ibm:aix:4.3
cpe:/o:ibm:aix:4.3.0
cpe:/o:ibm:aix:4.3.1
cpe:/o:ibm:aix:4.3.2
cpe:/o:ibm:aix:4.3.3
cpe:/o:ibm:aix:430
cpe:/o:ibm:aix:5
cpe:/o:ibm:aix:5.1
cpe:/o:ibm:aix:5.1.0.10
cpe:/o:ibm:aix:5.1l
cpe:/o:ibm:aix:5.2
cpe:/o:ibm:aix:5.2.0
cpe:/o:ibm:aix:5.2.0.50
cpe:/o:ibm:aix:5.2.0.54
cpe:/o:ibm:aix:5.2.2
cpe:/o:ibm:aix:5.2_l
cpe:/o:ibm:aix:5.3 and previous versions
cpe:/o:ibm:aix:5l
cpe:/o:ibm:aix:6.1 and previous versions
cpe:/o:ibm:aix:6.1.0
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

X Local [?]
Adjacent Network [?]
Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
Medium [?]
X Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
X Single [?]
None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

[Integrity Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

[Availability Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

Alternatives




References
AIXAPAR IZ84167




AIXAPAR IZ83975




AIXAPAR IZ83942




AIXAPAR IZ83909




AIXAPAR IZ82630




AIXAPAR IZ82245




AIXAPAR IZ81819




BID 43207




CONFIRM http://aix.software.ibm.com/aix/efixes/security/sa_snap_advisory.asc




SECTRACK 1024430




SECUNIA 41446




VUPEN ADV-2010-2377




Vulnerability Type Buffer Errors (CWE-119)




XF ibm-aix-sasnap-bo(61774)





Copyright © 2010 JPCERT/CC All Rights Reserved.