CVE-2006-2647

IBM AIX 5.1-5.3 - Untrusted Search Path Command Execution via update_flash

Title source: manual
STIX 2.1

Description

Untrusted search path vulnerability in update_flash for IBM AIX 5.1, 5.2 and 5.3 allows local users to execute arbitrary commands via unknown vectors involving lsmcode and possibly other commands.

References (7)

Core 7
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/2007
Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016166
Patch vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/search.wss?rs=0&q=IY88524&apar=only
Patch vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/search.wss?rs=0&q=IY85517&apar=only
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/18114
Patch vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/search.wss?rs=0&q=IY85518&apar=only
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/20325

Scores

EPSS 0.0040
EPSS Percentile 32.2%

Details

Status published
Products (3)
ibm/aix 5.1
ibm/aix 5.2
ibm/aix 5.3
Published May 30, 2006
Tracked Since Feb 18, 2026