IBM AIX LSVPD Local Privilege Escalation Vulnerability
BID:12061
Info
IBM AIX LSVPD Local Privilege Escalation Vulnerability
| Bugtraq ID: | 12061 |
| Class: | Unknown |
| CVE: |
CVE-2004-1054 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 21 2004 12:00AM |
| Updated: | Jul 12 2009 09:26AM |
| Credit: | Discovery of this vulnerability is credited to iDEFENSE Labs. |
| Vulnerable: |
IBM AIX 5.3 L IBM AIX 5.2.2 IBM AIX 5.2 L IBM AIX 5.1 L IBM AIX 5.3 IBM AIX 5.2 IBM AIX 5.1 |
| Not Vulnerable: | |
Discussion
IBM AIX LSVPD Local Privilege Escalation Vulnerability
The AIX 'lsvpd' utility is reported prone to an unspecified local privilege escalation vulnerability. The vendor describes that this vulnerability results from an insecure path handling issue.
Reports indicate that this issue may be exploited by any local user through the 'invscout' utility.
The AIX 'lsvpd' utility is reported prone to an unspecified local privilege escalation vulnerability. The vendor describes that this vulnerability results from an insecure path handling issue.
Reports indicate that this issue may be exploited by any local user through the 'invscout' utility.
Exploit / POC
IBM AIX LSVPD Local Privilege Escalation Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
IBM AIX LSVPD Local Privilege Escalation Vulnerability
Solution:
The vendor has released an advisory and APARs to address this vulnerability, please see the referenced advisory for further detail in regards to obtaining and installing appropriate APARs.
IBM AIX 5.1
IBM AIX 5.2
IBM AIX 5.3
Solution:
The vendor has released an advisory and APARs to address this vulnerability, please see the referenced advisory for further detail in regards to obtaining and installing appropriate APARs.
IBM AIX 5.1
IBM AIX 5.2
IBM AIX 5.3
References
IBM AIX LSVPD Local Privilege Escalation Vulnerability
References:
References: