CVE-2008-1599

The nddstat programs on IBM AIX 5.2, 5.3, and 6.1 do not properly handle environment variables, which allows local users to gain privileges by invoking (1) atmstat, (2) entstat, (3) fddistat, (4) hdlcstat, or (5) tokstat.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:ibm:aix:5.2:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:5.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:6.1:*:*:*:*:*:*:*

History

21 Nov 2024, 00:44

Type Values Removed Values Added
References () http://securitytracker.com/id?1019604 - () http://securitytracker.com/id?1019604 -
References () http://www.ibm.com/support/docview.wss?uid=isg1IZ16975 - Patch () http://www.ibm.com/support/docview.wss?uid=isg1IZ16975 - Patch
References () http://www.ibm.com/support/docview.wss?uid=isg1IZ16991 - Patch () http://www.ibm.com/support/docview.wss?uid=isg1IZ16991 - Patch
References () http://www.ibm.com/support/docview.wss?uid=isg1IZ17058 - Patch () http://www.ibm.com/support/docview.wss?uid=isg1IZ17058 - Patch
References () http://www.ibm.com/support/docview.wss?uid=isg1IZ17059 - Patch () http://www.ibm.com/support/docview.wss?uid=isg1IZ17059 - Patch
References () http://www.vupen.com/english/advisories/2008/0865 - () http://www.vupen.com/english/advisories/2008/0865 -
References () http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4156 - () http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4156 -
References () http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4157 - () http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4157 -
References () http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4158 - () http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4158 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5468 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5468 -

Information

Published : 2008-03-31 23:44

Updated : 2024-11-21 00:44


NVD link : CVE-2008-1599

Mitre link : CVE-2008-1599

CVE.ORG link : CVE-2008-1599


JSON object : View

Products Affected

ibm

  • aix
CWE
CWE-264

Permissions, Privileges, and Access Controls