Vulnerabilities > CVE-2004-1054 - Unspecified vulnerability in IBM AIX
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local users to gain privileges by modifying the PATH environment variable to point to a malicious "uname" program, which is executed from lsvpd after lsvpd has been invoked by invscout.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 7 |
Exploit-Db
description AIX 4.3/5.1 - 5.3 lsmcode Local Root Command Execution. CVE-2004-1054. Local exploit for aix platform id EDB-ID:701 last seen 2016-01-31 modified 2004-12-21 published 2004-12-21 reporter cees-bart source https://www.exploit-db.com/download/701/ title AIX 4.3/5.1 - 5.3 lsmcode Local Root Command Execution description AIX <= 5.3.0 (invscout) Local Command Execution Vulnerability. CVE-2004-1054. Local exploit for aix platform id EDB-ID:898 last seen 2016-01-31 modified 2005-03-25 published 2005-03-25 reporter ri0t source https://www.exploit-db.com/download/898/ title AIX <= 5.3.0 invscout Local Command Execution Vulnerability
Packetstorm
data source | https://packetstormsecurity.com/files/download/36794/getr00t.sh |
id | PACKETSTORM:36794 |
last seen | 2016-12-05 |
published | 2005-03-25 |
reporter | ri0t |
source | https://packetstormsecurity.com/files/36794/getr00t.sh.html |
title | getr00t.sh |
References
- http://www.idefense.com/application/poi/display?id=171&type=vulnerabilities
- http://www-1.ibm.com/support/search.wss?rs=0&q=IY64820&apar=only
- http://www-1.ibm.com/support/search.wss?rs=0&q=IY64852&apar=only
- http://www-1.ibm.com/support/search.wss?rs=0&q=IY64976&apar=only
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18619