PT-2001-1771 · Ibm · Aix
Publicado
2001-08-02
·
Atualizado
2017-10-10
·
CVE-2001-0573
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
AIX versions 4.x
Description:
The issue allows a local user to gain additional privileges by creating Trojan horse programs named
grep or lslv in a certain directory under the user's control. This causes lsfs to access the programs in that directory, potentially leading to privilege escalation.Recommendations:
For AIX version 4.x, consider restricting access to the lsfs command or removing execute permissions from the
grep and lslv programs in user-controlled directories to minimize the risk of exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Aix