Executive brief
A security flaw in the default configuration of the UUCP utility in older versions of the IBM AIX operating system allows local users to gain full administrative control. An attacker with basic access to the system could exploit this misconfiguration to take over the entire machine, potentially leading to data theft or system disruption. This issue affects AIX versions prior to 3.2.
Technical details
A privilege escalation vulnerability exists in the default configuration of the Unix-to-Unix Copy (UUCP) suite in IBM AIX versions prior to 3.2. The vulnerability stems from insecure default settings that allow a local, unprivileged user to execute commands or manipulate files with root-level permissions. An attacker with local shell access can exploit this misconfiguration to achieve a full system compromise. The issue was addressed in AIX 3.2 and later versions.
Affected products
- IBM AIX Before 3.2
Timeline
- 1992-03-19: disclosed: Initial publication date.
- 1992-03-19: advisory