First published: Wed Sep 27 2006(Updated: )
Untrusted search path vulnerability in acctctl in IBM AIX 5.3.0 allows local users to execute arbitrary commands by modifying the path to point to a malicious mkdir program.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM AIX | =5.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5010 is classified as a medium severity vulnerability due to its potential to allow local users to execute arbitrary commands.
To fix CVE-2006-5010, ensure that the environment variables related to the search path are configured securely and do not allow for the inclusion of untrusted directories.
CVE-2006-5010 affects local users of IBM AIX version 5.3.0.
Exploiting CVE-2006-5010 could allow an attacker to execute malicious commands on a compromised system with the privileges of the user running acctctl.
IBM has not provided a specific patch for CVE-2006-5010; mitigation involves properly configuring the system to avoid untrusted paths.