CVE-2004-1054 Information
Feb 14, 2021
cve
Description
Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0 5.2.0 and 5.3.0 allows local users to gain privileges by modifying the PATH environment variable to point to a malicious \uname\ program which is executed from lsvpd after lsvpd has been invoked by invscout.
Reference
http://www.idefense.com/application/poi/display?id=171&type=vulnerabilities http://www-1.ibm.com/support/search.wss?rs=0&q=IY64820&apar=only http://www-1.ibm.com/support/search.wss?rs=0&q=IY64852&apar=only http://www-1.ibm.com/support/search.wss?rs=0&q=IY64976&apar=only https://exchange.xforce.ibmcloud.com/vulnerabilities/18619
Share on: