MEDIUM
IBM AIX 5.3 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572
Published Jan 19, 2007
4.6
MEDIUMCVSS 2.0
EPSS 0.35%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.