CVE

Id
9482  
CVE No.
CVE-2004-1054  
Status
Candidate  
Description
Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local users to gain privileges by modifying the PATH environment variable to point to a malicious "uname" program, which is executed from lsvpd after lsvpd has been invoked by invscout.  
Phase
Assigned (20041118)  
Votes
None (candidate not yet proposed)  
Comments