CVE-2007-4622

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
05/11/2007
Last modified:
09/04/2025

Description

Integer underflow in the dns_name_fromtext function in (1) libdns_nonsecure.a and (2) libdns_secure.a in IBM AIX 5.2 allows local users to gain privileges via a crafted "-y" (TSIG key) command line argument to dig.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ibm:aix:5.2:*:*:*:*:*:*:*