Executive brief
A security vulnerability exists in the 'rcp' command of the IBM AIX operating system, which is used for copying files between computers. A person with basic access to the system could exploit this flaw to gain full administrative control (root access). This would allow them to view, modify, or delete any data on the machine and disrupt operations.
Technical details
A buffer overflow vulnerability exists in the 'rcp' (remote copy) utility on IBM AIX systems. The flaw is triggered when the utility handles improperly validated input, leading to memory corruption. Because 'rcp' often runs with elevated privileges to facilitate file transfers, a local attacker can exploit this overflow to execute arbitrary code with root-level permissions. This is a classic local privilege escalation (LPE) vulnerability requiring only local shell access to the affected system.
Affected products
- IBM AIX
Timeline
- 1997-10-01: disclosed: NVD Published Date