CVE Vulnerabilities

CVE-2008-1599

Published: Mar 31, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The nddstat programs on IBM AIX 5.2, 5.3, and 6.1 do not properly handle environment variables, which allows local users to gain privileges by invoking (1) atmstat, (2) entstat, (3) fddistat, (4) hdlcstat, or (5) tokstat.

Affected Software

NameVendorStart VersionEnd Version
AixIbm5.2 (including)5.2 (including)
AixIbm5.3 (including)5.3 (including)
AixIbm6.1 (including)6.1 (including)

References