CVE-2007-2996

high

Description

Unspecified vulnerability in perl.rte 5.8.0.10 through 5.8.0.95 on IBM AIX 5.2, and 5.8.2.10 through 5.8.2.50 on AIX 5.3, allows local users to gain privileges via unspecified vectors related to the installation and "waiting for a legitimate user to execute a binary that ships with Perl."

References

http://www.vupen.com/english/advisories/2007/2004

http://www.securitytracker.com/id?1018177

http://www.securityfocus.com/bid/24241

http://www-1.ibm.com/support/search.wss?rs=0&q=IY98396&apar=only

http://www-1.ibm.com/support/docview.wss?uid=isg1IY98395

http://www-1.ibm.com/support/docview.wss?uid=isg1IY98394

http://secunia.com/advisories/25478

http://osvdb.org/36754

Details

Source: Mitre, NVD

Published: 2007-06-04

Updated: 2025-04-09

Risk Information

CVSS v2

Base Score: 6.6

Vector: CVSS2#AV:L/AC:M/Au:S/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00044