CVE-2004-2697: Race Condition
The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to gain privileges via a symlink attack on a command line argument (log file). NOTE: this might be related to CVE-2006-5002.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2697?
CVE-2004-2697 is considered a high severity vulnerability due to its potential to allow local privilege escalation.
How do I fix CVE-2004-2697?
To fix CVE-2004-2697, users should apply any available patches for Inventory Scout daemon or update the software to a version that mitigates this vulnerability.
Who is affected by CVE-2004-2697?
CVE-2004-2697 affects local users of the Inventory Scout daemon on IBM AIX versions 4.3.3 and 5.1.
What type of attack is related to CVE-2004-2697?
CVE-2004-2697 is related to a symlink attack which allows local users to gain elevated privileges.
What versions of AIX are vulnerable to CVE-2004-2697?
The vulnerable versions of AIX are 4.3.3 and 5.1, including sub-version 5.1l.