troubleshooting Question

Disable setuid bit on AIX.

Avatar of sminfo
sminfo asked on
Unix OS
6 Comments3 Solutions1476 ViewsLast Modified:
wmp, this's for you :-)

Our company was audited. One of the vulnerabilities was:

"AIX-VULN005

setuid bit enabled"        

set user ID upon execution is an access right flags that allow users to run an executable with the permissions of the executable's owner or group. Successful buffer overrun attacks on vulnerable applications allow the attacker to execute arbitrary code under the rights of the process being exploited.      

 MEDIUM

HIGH  

Review these privileges to determine if this is a configuration according to the business needs.
 
I know what setuid is, but not clear if there's a global setup in AIX. As you see, the vulnerability is global "setuid bit enabled"

Any hint on how to solve this?

Thanks.
ASKER CERTIFIED SOLUTION
sjm_ee

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Log in to continue reading
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform for $9.99/mo
View membership options
Unlock 3 Answers and 6 Comments.
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
See how we're fighting big data
The Value of Experts Exchange in My Daily IT Life

Experts Exchange (EE) has become my company's go-to resource to get answers. I've used EE to make decisions, solve problems and even save customers. OutagesIO has been a challenging project and... Keep reading >>

Mike

Owner of Outages.IO
Phoenix, Arizona, United States
Member Since 2016
Join a full scale community that combines the best parts of other tools into one platform.
Unlock 3 Answers and 6 Comments.
View membership options
“All of life is about relationships, and EE has made a virtual community a real community. It lifts everyone's boat.”
William Peck

Member since 2004