AIX 5.3 TL 7 : pioout (IZ10842)
High Nessus Plugin ID 64312
SynopsisThe remote AIX host is missing a security patch.
DescriptionBuffer overflow vulnerabilities exist in the 'printers.rte' fileset commands listed below. A local attacker may execute arbitrary code with root privileges because the commands are setuid root.
The following commands are vulnerable :
/usr/lib/lpd/pio/etc/pioout The fix for piomkpq for IZ01121 and IZ01122 was not included with this fix package, therefore it has been repackged and included as described below. A local attacker who is a member of the printq group may execute arbitrary code with root privileges because the piomkpq command is setuid root. The following command is vulnerable: /usr/lib/lpd/pio/etc/piomkpq.
SolutionInstall the appropriate interim fix.