← Back

CVE-2004-1054

nvd nist
Published: Jan 10, 2005Modified: Apr 16, 2026

JSON object

Loading...
7.2
Vector
AV:L/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 3.9 / Impact: 10.0
Source: NVD

Description

Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local users to gain privileges by modifying the PATH environment variable to point to a malicious "uname" program, which is executed from lsvpd after lsvpd has been invoked by invscout.

Affected (7)

Products: Ibm: Aix
1 product
Aix
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version 5.1
Version 5.1l
Version 5.2.2
Version 5.2
Version 5.2_l
Version 5.3
Version 5.3_l

Timeline

No history available yet.