CVE-2004-1054: High severity IBM AIX vulnerability
Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local users to gain privileges by modifying the PATH environment variable to point to a malicious "uname" program, which is executed from lsvpd after lsvpd has been invoked by invscout.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1054?
CVE-2004-1054 is considered a high severity vulnerability due to its potential to allow local users to gain elevated privileges.
How do I fix CVE-2004-1054?
To mitigate CVE-2004-1054, users should avoid allowing untrusted modifications to the PATH environment variable and apply any security patches provided by IBM.
Who is affected by CVE-2004-1054?
CVE-2004-1054 affects local users on IBM AIX versions 5.1.0, 5.2.0, and 5.3.0.
What causes CVE-2004-1054?
CVE-2004-1054 is caused by the invscout program executing a malicious 'uname' program pointed to by a modified PATH environment variable.
Can CVE-2004-1054 be exploited remotely?
No, CVE-2004-1054 requires local access to the system, making it a local privilege escalation vulnerability.