CVE-2004-2388: Critical severity IBM AIX vulnerability
Published Dec 31, 2004
·Updated
rexecd for AIX 4.3.3 does not properly use a local copy of the pwd structure when calling getpwnam, which may cause the structure to be overwritten by the authenticate function and assign privileges to the wrong user.
Affected Software
1 affected component
IBM AIX=4.3.3
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Aug 16, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2388?
CVE-2004-2388 is considered a critical vulnerability due to the potential for privilege escalation.
2
How do I fix CVE-2004-2388?
To fix CVE-2004-2388, upgrade to a patched version of AIX that resolves this security issue.
3
What systems are impacted by CVE-2004-2388?
CVE-2004-2388 affects IBM AIX version 4.3.3.
4
What type of vulnerability is CVE-2004-2388?
CVE-2004-2388 is a local privilege escalation vulnerability resulting from improper handling of user authentication.
5
Can CVE-2004-2388 be exploited remotely?
CVE-2004-2388 requires local access for exploitation, but it can allow an attacker to gain higher privileges.