CVE-2004-0828
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/11/2004
Last modified:
20/11/2024
Description
The ctstrtcasd program in RSCT 2.3.0.0 and earlier on IBM AIX 5.2 and 5.3 does not properly drop privileges before executing the -f option, which allows local users to modify or create arbitrary files.
Impact
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:ibm:aix:5.2:*:*:*:*:*:*:* | ||
cpe:2.3:o:ibm:aix:5.3:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://secunia.com/advisories/12664/
- http://securitytracker.com/id?1011429=
- http://www.securityfocus.com/bid/11264
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17514
- http://secunia.com/advisories/12664/
- http://securitytracker.com/id?1011429=
- http://www.securityfocus.com/bid/11264
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17514