CVE-2001-0573IBM AIX vulnerability

4 documents4 sources
Severity
4.6MEDIUMNVD
EPSS
0.3%
top 43.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 2
Latest updateApr 30

Description

lsfs in AIX 4.x allows a local user to gain additional privileges by creating Trojan horse programs named (1) grep or (2) lslv in a certain directory that is under the user's control, which cause lsfs to access the programs in that directory.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages1 packages

NVDibm/aix4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vw5c-mpv8-qjf6: lsfs in AIX 42022-04-30
CVEList
CVE-2001-0573: lsfs in AIX 42002-03-09

💥Exploits & PoCs

1
Exploit-DB
BeroFTPD 1.3.4(1) (Linux x86) - Remote Code Execution2001-05-08
CVE-2001-0573 — IBM AIX vulnerability | cvebase