CVE Vulnerabilities

CVE-2004-1054

Published: Jan 10, 2005 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local users to gain privileges by modifying the PATH environment variable to point to a malicious uname program, which is executed from lsvpd after lsvpd has been invoked by invscout.

Affected Software

Name Vendor Start Version End Version
Aix Ibm 5.1 (including) 5.1 (including)
Aix Ibm 5.1l (including) 5.1l (including)
Aix Ibm 5.2 (including) 5.2 (including)
Aix Ibm 5.2.2 (including) 5.2.2 (including)
Aix Ibm 5.2_l (including) 5.2_l (including)
Aix Ibm 5.3 (including) 5.3 (including)
Aix Ibm 5.3_l (including) 5.3_l (including)

References