CVE Vulnerabilities

CVE-2004-0828

Published: Nov 03, 2004 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The ctstrtcasd program in RSCT 2.3.0.0 and earlier on IBM AIX 5.2 and 5.3 does not properly drop privileges before executing the -f option, which allows local users to modify or create arbitrary files.

Affected Software

Name Vendor Start Version End Version
Aix Ibm 5.2 (including) 5.2 (including)
Aix Ibm 5.3 (including) 5.3 (including)

References