Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2001-1080

Overview

Vulnerability Score 10.0 10.0
CVE Id CVE-2001-1080
Last Modified 05 Sep 2008 04:25:38
Published 19 Jun 2001 12:00:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2001-1080

Summary

diagrpt in AIX 4.3.x and 5.1 uses the DIAGDATADIR environment variable to find and execute certain programs, which allows local users to gain privileges by modifying the variable to point to a Trojan horse program.

Vulnerable Systems

Operating System

  • Ibm Aix 4.3

  • Ibm Aix 5.1


References

IBM - MSS-OAR-E01-2001:225.1

XF - aix-diagrpt-root-shell(6734)

BID - 2916


Last Updated: 27 May 2016 10:36:31