Lucene search

K
nvd[email protected]NVD:CVE-2004-1054
HistoryJan 10, 2005 - 5:00 a.m.

CVE-2004-1054

2005-01-1005:00:00
web.nvd.nist.gov
2

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.4

Confidence

High

EPSS

0

Percentile

0.4%

Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local users to gain privileges by modifying the PATH environment variable to point to a malicious “uname” program, which is executed from lsvpd after lsvpd has been invoked by invscout.

Affected configurations

Nvd
Node
ibmaixMatch5.1
OR
ibmaixMatch5.1l
OR
ibmaixMatch5.2
OR
ibmaixMatch5.2.2
OR
ibmaixMatch5.2_l
OR
ibmaixMatch5.3
OR
ibmaixMatch5.3_l
VendorProductVersionCPE
ibmaix5.1cpe:2.3:o:ibm:aix:5.1:*:*:*:*:*:*:*
ibmaix5.1lcpe:2.3:o:ibm:aix:5.1l:*:*:*:*:*:*:*
ibmaix5.2cpe:2.3:o:ibm:aix:5.2:*:*:*:*:*:*:*
ibmaix5.2.2cpe:2.3:o:ibm:aix:5.2.2:*:*:*:*:*:*:*
ibmaix5.2_lcpe:2.3:o:ibm:aix:5.2_l:*:*:*:*:*:*:*
ibmaix5.3cpe:2.3:o:ibm:aix:5.3:*:*:*:*:*:*:*
ibmaix5.3_lcpe:2.3:o:ibm:aix:5.3_l:*:*:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.4

Confidence

High

EPSS

0

Percentile

0.4%