CVE-2000-1222: High severity IBM AIX vulnerability
Published Dec 10, 2000
·Updated
AIX sysback before 4.2.1.13 uses a relative path to find and execute the hostname program, which allows local users to gain privileges by modifying the path to point to a malicious hostname program.
Affected Software
1 affected component
IBM AIX<=4.2.1.12
Event History
Dec 10, 2000
CVE Published
05:00 AM
Apr 21, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-1222?
CVE-2000-1222 is classified as a high-severity vulnerability due to its potential for privilege escalation by local users.
2
How do I fix CVE-2000-1222?
To fix CVE-2000-1222, upgrade to AIX sysback version 4.2.1.13 or later.
3
Who is affected by CVE-2000-1222?
CVE-2000-1222 affects users running AIX sysback versions prior to 4.2.1.13.
4
What is the exploitation method of CVE-2000-1222?
CVE-2000-1222 can be exploited by modifying the PATH environment variable to execute a malicious hostname program.
5
What impact does CVE-2000-1222 have on system security?
The impact of CVE-2000-1222 allows unauthorized privilege escalation, potentially leading to system compromise.