Executive brief
A vulnerability in the AIX operating system's network diagnostic tool, nslookup, allows a local user to gain full administrative control of the system. This occurs because the tool does not properly relinquish its high-level system privileges when performing certain tasks. An attacker with basic access to the machine could exploit this to bypass security controls, access sensitive data, or disrupt operations.
Technical details
The nslookup utility in IBM AIX fails to properly drop setuid root privileges during execution. This flaw allows a local, unprivileged user to execute commands or manipulate the system with the elevated permissions of the root user. The vulnerability is categorized as a privilege management issue where the application retains more authority than necessary for its intended function. An attacker must have local shell access to the affected system to exploit this vulnerability. Successful exploitation results in a complete compromise of confidentiality, integrity, and availability.
Affected products
- IBM AIX
Timeline
- 1997-10-29: disclosed