Executive brief
A security vulnerability in the Display PostScript (DPS) server on older IBM AIX systems could allow a local user to gain full administrative control. By exploiting a flaw in how the system handles file permissions when running under the X Display Manager, an attacker can overwrite critical system files. This could lead to a total system compromise, data loss, or permanent disruption of operations.
Technical details
A privilege escalation vulnerability exists in the dpsexec (Display PostScript Server) executable when managed by the X Display Manager (XDM) in IBM AIX versions 3.2.5 and prior. The root cause is an improper privilege check that allows a local, unprivileged user to trigger file operations with elevated permissions. By exploiting this flaw, an attacker can overwrite arbitrary files on the filesystem, including sensitive configuration or system binaries. Successful exploitation typically results in the attacker gaining root-level access to the affected host. This is a legacy vulnerability originally disclosed in 1994.
Affected products
- IBM AIX 3.2.5 and earlier
Timeline
- 1994-07-20: disclosed: Initial public disclosure via Bugtraq and NVD publication