CVE-2007-4217
published 2007-11-05CVE-2007-4217: Stack-based buffer overflow in the domacro function in ftp in IBM AIX 5.2 and 5.3 allows local users to gain privileges via a long parameter to a macro, as…
PriorityP428high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.41%
33.3th percentile
Stack-based buffer overflow in the domacro function in ftp in IBM AIX 5.2 and 5.3 allows local users to gain privileges via a long parameter to a macro, as demonstrated by executing a macro via the '$' command.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | aix | — | — |
| ibm | aix | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
CWE
Improper Privilege Management
mitre_cwe
CWE-269 Improper Privilege Management
CWE-269: Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Modes of Introduction:
Phase: Architecture and Design
Phase: Implementation
Note: REALIZATION: This weakness is caused during implementation of an architectural security tactic.
Phase: Operation
Common Consequences:
Scope: Access Control. Impact: Gain Privileges or Assume Identity.
Detection Methods:
Automated Static Analysis: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and contro
CWE
Execution with Unnecessary Privileges
mitre_cwe
CWE-250 Execution with Unnecessary Privileges
CWE-250: Execution with Unnecessary Privileges
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
Modes of Introduction:
Phase: Implementation
Note: REALIZATION: This weakness is caused during implementation of an architectural security tactic.
Phase: Installation
Phase: Architecture and Design
Note: If an application has this design problem, then it can be easier for the developer to make implementation-related errors such as CWE-271 (Privilege Dropping / Lowering Errors). In addition, the consequences of Privilege Chaining (CWE-268) can become more severe.
Phase: Operation
Common Consequences:
Scope: Confidentiality, Integrity, Availability, Access Contro
ftp://aix.software.ibm.com/aix/efixes/security/ftp_ifix.tarhttp://labs.idefense.com/intelligence/vulnerabilities/display.php?id=616http://secunia.com/advisories/27437http://securitytracker.com/id?1018871http://www.ibm.com/support/docview.wss?uid=isg1IZ05487http://www.ibm.com/support/docview.wss?uid=isg1IZ05488http://www.securityfocus.com/bid/26260http://www.vupen.com/english/advisories/2007/3669http://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&heading=AIX53&path=%2F200709%2FSECURITY%2F20070905%2Fdatafile101815https://exchange.xforce.ibmcloud.com/vulnerabilities/38162ftp://aix.software.ibm.com/aix/efixes/security/ftp_ifix.tarhttp://labs.idefense.com/intelligence/vulnerabilities/display.php?id=616http://secunia.com/advisories/27437http://securitytracker.com/id?1018871http://www.ibm.com/support/docview.wss?uid=isg1IZ05487http://www.ibm.com/support/docview.wss?uid=isg1IZ05488http://www.securityfocus.com/bid/26260http://www.vupen.com/english/advisories/2007/3669http://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&heading=AIX53&path=%2F200709%2FSECURITY%2F20070905%2Fdatafile101815https://exchange.xforce.ibmcloud.com/vulnerabilities/38162
2007-11-05
Published