First published: Sun Dec 10 2000(Updated: )
AIX sysback before 4.2.1.13 uses a relative path to find and execute the hostname program, which allows local users to gain privileges by modifying the path to point to a malicious hostname program.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM AIX | <=4.2.1.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-1222 is classified as a high-severity vulnerability due to its potential for privilege escalation by local users.
To fix CVE-2000-1222, upgrade to AIX sysback version 4.2.1.13 or later.
CVE-2000-1222 affects users running AIX sysback versions prior to 4.2.1.13.
CVE-2000-1222 can be exploited by modifying the PATH environment variable to execute a malicious hostname program.
The impact of CVE-2000-1222 allows unauthorized privilege escalation, potentially leading to system compromise.