AIX : Multiple Vulnerabilities (IJ55695)

high Nessus Plugin ID 270141

Synopsis

The remote AIX host is missing a security patch.

Description

The version of AIX installed on the remote host is prior to APAR IJ55695. It is, therefore, affected by multiple vulnerabilities as referenced in the IJ55695 advisory.

- A flaw was found in the X Record extension. The RecordSanityCheckRegisterClients function does not check for an integer overflow when computing request length, which allows a client to bypass length checks.
(CVE-2025-49179)

- A flaw was found in the X Rendering extension's handling of animated cursors. If a client provides no cursors, the server assumes at least one is present, leading to an out-of-bounds read and potential crash.
(CVE-2025-49175)

- A flaw was found in the Big Requests extension. The request length is multiplied by 4 before checking against the maximum allowed size, potentially causing an integer overflow and bypassing the size check.
(CVE-2025-49176)

- A flaw was found in the X server's request handling. Non-zero 'bytes to ignore' in a client's request can cause the server to skip processing another client's request, potentially leading to a denial of service.
(CVE-2025-49178)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Please apply the appropriate interim fix per APAR IJ55695.

See Also

https://www.ibm.com/support/pages/node/7247777

https://www.ibm.com/support/pages/apar/IJ55695

Plugin Details

Severity: High

ID: 270141

File Name: aix_IJ55695.nasl

Version: 1.1

Type: local

Published: 10/13/2025

Updated: 10/13/2025

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.3

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-49179

CVSS v3

Risk Factor: High

Base Score: 7.3

Temporal Score: 6.4

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/AIX/version, Host/AIX/lslpp

Exploit Ease: No known exploits are available

Patch Publication Date: 10/13/2025

Vulnerability Publication Date: 6/17/2025

Reference Information

CVE: CVE-2025-49175, CVE-2025-49176, CVE-2025-49178, CVE-2025-49179