CVE Vulnerabilities

CVE-2004-1329

Published: Dec 20, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd in AIX 5.1 through 5.3 allows local users to execute arbitrary programs by modifying the DIAGNOSTICS environment variable to point to a malicious Dctrl program.

Affected Software

NameVendorStart VersionEnd Version
AixIbm5.1 (including)5.1 (including)
AixIbm5.1l (including)5.1l (including)
AixIbm5.2 (including)5.2 (including)
AixIbm5.2.2 (including)5.2.2 (including)
AixIbm5.2_l (including)5.2_l (including)
AixIbm5.3 (including)5.3 (including)
AixIbm5.3_l (including)5.3_l (including)

References