CVE-2006-5010: High severity IBM AIX vulnerability
Untrusted search path vulnerability in acctctl in IBM AIX 5.3.0 allows local users to execute arbitrary commands by modifying the path to point to a malicious mkdir program.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5010?
CVE-2006-5010 is classified as a medium severity vulnerability due to its potential to allow local users to execute arbitrary commands.
How do I fix CVE-2006-5010?
To fix CVE-2006-5010, ensure that the environment variables related to the search path are configured securely and do not allow for the inclusion of untrusted directories.
Who is affected by CVE-2006-5010?
CVE-2006-5010 affects local users of IBM AIX version 5.3.0.
What are the implications of exploiting CVE-2006-5010?
Exploiting CVE-2006-5010 could allow an attacker to execute malicious commands on a compromised system with the privileges of the user running acctctl.
Is there a patch available for CVE-2006-5010?
IBM has not provided a specific patch for CVE-2006-5010; mitigation involves properly configuring the system to avoid untrusted paths.