Vulnerabilities > CVE-2006-5011 - Local Arbitrary Command Execution vulnerability in IBM AIX 5.2.0/5.3.0

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
ibm
nessus

Summary

Untrusted search path vulnerability in snappd in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via a Trojan horse program, involving the "system subroutine".

Vulnerable Configurations

Part Description Count
OS
Ibm
2

Nessus

  • NASL familyAIX Local Security Checks
    NASL idAIX_U809493.NASL
    descriptionThe remote host is missing AIX PTF U809493, which is related to the security of the package bos.net.snapp.
    last seen2020-06-01
    modified2020-06-02
    plugin id28741
    published2007-12-03
    reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/28741
    titleAIX 5.3 TL 5 / 5.3 TL 6 : bos.net.snapp (U809493)
  • NASL familyAIX Local Security Checks
    NASL idAIX_U808279.NASL
    descriptionThe remote host is missing AIX PTF U808279, which is related to the security of the package bos.net.snapp.
    last seen2020-06-01
    modified2020-06-02
    plugin id28676
    published2007-12-03
    reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/28676
    titleAIX 5.2 TL 9 / 5.2 TL 10 : bos.net.snapp (U808279)