CVE-2004-1054

Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local users to gain privileges by modifying the PATH environment variable to point to a malicious "uname" program, which is executed from lsvpd after lsvpd has been invoked by invscout.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:ibm:aix:5.1:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:5.1l:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:5.2:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:5.2.2:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:5.2_l:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:5.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:5.3_l:*:*:*:*:*:*:*

History

20 Nov 2024, 23:49

Type Values Removed Values Added
References () http://www-1.ibm.com/support/search.wss?rs=0&q=IY64820&apar=only - () http://www-1.ibm.com/support/search.wss?rs=0&q=IY64820&apar=only -
References () http://www-1.ibm.com/support/search.wss?rs=0&q=IY64852&apar=only - () http://www-1.ibm.com/support/search.wss?rs=0&q=IY64852&apar=only -
References () http://www-1.ibm.com/support/search.wss?rs=0&q=IY64976&apar=only - () http://www-1.ibm.com/support/search.wss?rs=0&q=IY64976&apar=only -
References () http://www.idefense.com/application/poi/display?id=171&type=vulnerabilities - Vendor Advisory () http://www.idefense.com/application/poi/display?id=171&type=vulnerabilities - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/18619 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/18619 -

Information

Published : 2005-01-10 05:00

Updated : 2024-11-20 23:49


NVD link : CVE-2004-1054

Mitre link : CVE-2004-1054

CVE.ORG link : CVE-2004-1054


JSON object : View

Products Affected

ibm

  • aix