CVE Database
/

CVE-2004-2388

Back to search

CVE-2004-2388

Published: Aug 16, 2005

Modified: Aug 8, 2024

PUBLISHED

Description

rexecd for AIX 4.3.3 does not properly use a local copy of the pwd structure when calling getpwnam, which may cause the structure to be overwritten by the authenticate function and assign privileges to the wrong user.

VendorProductVersions

n/a

n/a

affected
n/a

References

11085
third-party-advisory
x_refsource_SECUNIA
O-102
third-party-advisory
government-resource
x_refsource_CIAC
rexecd-gain-privileges(15455)
vdb-entry
x_refsource_XF
IY53507
vendor-advisory
x_refsource_AIXAPAR
9835
vdb-entry
x_refsource_BID
4248
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now