CVE-2004-0544
published 2004-08-06CVE-2004-0544: Multiple buffer overflows in LVM for AIX 5.1 and 5.2 allow local users to gain privileges via the (1) putlvcb or (2) getlvcb commands.
PriorityP430high7.2CVSS 2.0
AVLACLAuNCCICAC
EXPLOIT
EPSS
1.22%
65.6th percentile
Multiple buffer overflows in LVM for AIX 5.1 and 5.2 allow local users to gain privileges via the (1) putlvcb or (2) getlvcb commands.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q78h-6xwh-h7pw: Multiple buffer overflows in LVM for AIX 5
ghsa_unreviewed·2022-04-29
CVE-2004-0544 [HIGH] GHSA-q78h-6xwh-h7pw: Multiple buffer overflows in LVM for AIX 5
Multiple buffer overflows in LVM for AIX 5.1 and 5.2 allow local users to gain privileges via the (1) putlvcb or (2) getlvcb commands.
Red Hat
CVE-2005-1730: Multiple vulnerabilities in the OpenSSL ASN
vendor_redhat·CVSS 5.0
CVE-2005-1730 [MEDIUM] CVE-2005-1730: Multiple vulnerabilities in the OpenSSL ASN
Multiple vulnerabilities in the OpenSSL ASN.1 parser, as used in Novell iManager 2.0.2, allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted packets, as demonstrated by "OpenSSL ASN.1 brute forcer." NOTE: this issue might overlap CVE-2004-0079, CVE-2004-0081, or CVE-2004-0112.
Statement: Based on our research we believe that the "OpenSSL ASN.1 brute forcer." is actually exploiting flaws CVE-2003-0543, CVE-2003-0544, CVE-2003-0545. Those issues are all addressed in Red Hat Enterprise Linux and therefore CVE-2005-1730 is a duplicate assignment.
No detection rules found.
Exploit-DB
AIX 4.3.3/5.x - Getlvcb Command Line Argument Buffer Overflow (2)
exploitdb·2004-03-17
CVE-2004-0544 AIX 4.3.3/5.x - Getlvcb Command Line Argument Buffer Overflow (2)
AIX 4.3.3/5.x - Getlvcb Command Line Argument Buffer Overflow (2)
---
// source: https://www.securityfocus.com/bid/9905/info
getlvcb has been reported to be prone to a buffer overflow vulnerability.
When an argument is passed to the getlvcb utility, the string is copied into a reserved buffer in memory. Data that exceeds the size of the reserved buffer will overflow its bounds and will trample any saved data that is adjacent to the affected buffer. Ultimately this may lead to the execution of arbitrary instructions in the context of the root user.
An attacker will require system group privileges prior to the execution of the getlvcb utility, the attacker may exploit the issue described in BID 9903 in order to gain the necessary privileges required to exploit this vulnerability.
/****
Exploit-DB
AIX 4.3.3/5.x - Getlvcb Command Line Argument Buffer Overflow (1)
exploitdb·2003-05-30
CVE-2004-0544 AIX 4.3.3/5.x - Getlvcb Command Line Argument Buffer Overflow (1)
AIX 4.3.3/5.x - Getlvcb Command Line Argument Buffer Overflow (1)
---
source: https://www.securityfocus.com/bid/9905/info
getlvcb has been reported to be prone to a buffer overflow vulnerability.
When an argument is passed to the getlvcb utility, the string is copied into a reserved buffer in memory. Data that exceeds the size of the reserved buffer will overflow its bounds and will trample any saved data that is adjacent to the affected buffer. Ultimately this may lead to the execution of arbitrary instructions in the context of the root user.
An attacker will require system group privileges prior to the execution of the getlvcb utility, the attacker may exploit the issue described in BID 9903 in order to gain the necessary privileges required to exploit this vulnerability.
#!/usr/b
No writeups or analysis indexed.
http://secunia.com/advisories/11158/http://www-1.ibm.com/services/continuity/recover1.nsf/mss/MSS-OAR-E01-2004.0544.2http://www-1.ibm.com/support/docview.wss?uid=isg1IY55681http://www-1.ibm.com/support/docview.wss?uid=isg1IY55682http://www.ciac.org/ciac/bulletins/o-131.shtmlhttp://www.osvdb.org/4392http://www.osvdb.org/4393http://www.securityfocus.com/bid/9905http://www.securityfocus.com/bid/9906https://exchange.xforce.ibmcloud.com/vulnerabilities/15555https://exchange.xforce.ibmcloud.com/vulnerabilities/18317http://secunia.com/advisories/11158/http://www-1.ibm.com/services/continuity/recover1.nsf/mss/MSS-OAR-E01-2004.0544.2http://www-1.ibm.com/support/docview.wss?uid=isg1IY55681http://www-1.ibm.com/support/docview.wss?uid=isg1IY55682http://www.ciac.org/ciac/bulletins/o-131.shtmlhttp://www.osvdb.org/4392http://www.osvdb.org/4393http://www.securityfocus.com/bid/9905http://www.securityfocus.com/bid/9906https://exchange.xforce.ibmcloud.com/vulnerabilities/15555https://exchange.xforce.ibmcloud.com/vulnerabilities/18317
2004-08-06
Published