← back
CVE-2009-2669

CVE-2009-2669

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 0.7%
from disclosure to weapon37 days
Published on NVDAug 5
1st PoC+37d
exploitation probability
0.7%top 50% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A certain debugging component in IBM AIX 5.3 and 6.1 does not properly handle the (1) _LIB_INIT_DBG and (2) _LIB_INIT_DBG_FILE environment variables, which allows local users to gain privileges by leveraging a setuid-root program to create an arbitrary root-owned file with world-writable permissions, related to libC.a (aka the XL C++ runtime library) in AIX 5.3 and libc.a in AIX 6.1.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.