CVE-2014-3074: IBM Aix
High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.
The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, by setting crafted MALLOCOPTIONS and MALLOCBUCKETS environment-variable values and then executing a setuid program.
Affected products
- IBM Aix: version 6.1 only; version 7.1 only
- IBM Vios: version 2.2.0.10 only; version 2.2.0.11 only; version 2.2.0.12 only; version 2.2.0.13 only; version 2.2.1.0 only; version 2.2.1.1 only; …
Published 2014-07-02. Last modified 2026-06-17.