CVE Vulnerabilities

CVE-2004-1329

Published: Dec 20, 2004 | Modified: Oct 19, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd in AIX 5.1 through 5.3 allows local users to execute arbitrary programs by modifying the DIAGNOSTICS environment variable to point to a malicious Dctrl program.

Affected Software

Name Vendor Start Version End Version
Aix Ibm 5.1 (including) 5.1 (including)
Aix Ibm 5.1l (including) 5.1l (including)
Aix Ibm 5.2 (including) 5.2 (including)
Aix Ibm 5.2.2 (including) 5.2.2 (including)
Aix Ibm 5.2_l (including) 5.2_l (including)
Aix Ibm 5.3 (including) 5.3 (including)
Aix Ibm 5.3_l (including) 5.3_l (including)

References