CVE-2004-1329
Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd in AIX 5.1 through 5.3 allows local users to execute arbitrary programs by modifying the DIAGNOSTICS environment variable to point to a malicious Dctrl program.
- Affected products
- Aix
- Ibm Aix
- = 5.1, 5.1l, 5.2, 5.2.2, 5.2_l, 5.3, 5.3_l
- CVSS 2.0
- 7.2 HIGH
- EPSS
- 3.3% (87th percentile)
- NVD status
- Modified
- Published
- 2005-01-06
CVE-2004-1329 at NVD
2 known exploits for CVE-2004-1329
Proof-of-concept code and exploit modules indexed by Sploitus