PT-2001-1771 · Ibm · Aix
Published
2001-08-02
·
Updated
2017-10-10
·
CVE-2001-0573
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
AIX versions 4.x
Description:
The issue allows a local user to gain additional privileges by creating Trojan horse programs named
grep or lslv in a certain directory under the user's control. This causes lsfs to access the programs in that directory, potentially leading to privilege escalation.Recommendations:
For AIX version 4.x, consider restricting access to the lsfs command or removing execute permissions from the
grep and lslv programs in user-controlled directories to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aix