VulnerabilityModified
CVE-2009-0370
Multiple unspecified vulnerabilities in IBM AIX 5.2.0 through 6.1.2 allow local users to append data to arbitrary files, related to (1) rmsock and (2) rmsock64 not creating "secure log files."
HIGH 7.2EPSS 0.37%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.37%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple unspecified vulnerabilities in IBM AIX 5.2.0 through 6.1.2 allow local users to append data to arbitrary files, related to (1) rmsock and (2) rmsock64 not creating "secure log files."
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.37% probability · 30th percentile
- CISA KEV
- Not listed
- Affected
- ibm/aix
- Source
- cve@mitre.org
References
- http://aix.software.ibm.com/aix/efixes/security/rmsock_advisory.asc
- http://www.ibm.com/support/docview.wss?uid=isg1IZ40386Patch
- http://www.ibm.com/support/docview.wss?uid=isg1IZ41510Patch
- http://www.ibm.com/support/docview.wss?uid=isg1IZ41593
- http://www.ibm.com/support/docview.wss?uid=isg1IZ41599Patch
- http://www.ibm.com/support/docview.wss?uid=isg1IZ42785Patch
- http://www.ibm.com/support/docview.wss?uid=isg1IZ42786Patch
- http://www.ibm.com/support/docview.wss?uid=isg1IZ42787Patch
- http://www.ibm.com/support/docview.wss?uid=isg1IZ42788Patch
- http://www.securityfocus.com/bid/33522Patch
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6028
- http://aix.software.ibm.com/aix/efixes/security/rmsock_advisory.asc
- http://www.ibm.com/support/docview.wss?uid=isg1IZ40386Patch
- http://www.ibm.com/support/docview.wss?uid=isg1IZ41510Patch
- http://www.ibm.com/support/docview.wss?uid=isg1IZ41593
- http://www.ibm.com/support/docview.wss?uid=isg1IZ41599Patch
- http://www.ibm.com/support/docview.wss?uid=isg1IZ42785Patch
- http://www.ibm.com/support/docview.wss?uid=isg1IZ42786Patch
- http://www.ibm.com/support/docview.wss?uid=isg1IZ42787Patch
- http://www.ibm.com/support/docview.wss?uid=isg1IZ42788Patch
- http://www.securityfocus.com/bid/33522Patch
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6028
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.