CVE-2004-2697

IBM Aix - Race Condition

Title source: rule

Description

The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to gain privileges via a symlink attack on a command line argument (log file). NOTE: this might be related to CVE-2006-5002.

Exploits (1)

exploitdb WORKING POC VERIFIED
by watercloud · perllocalaix
https://www.exploit-db.com/exploits/23883

Scores

EPSS 0.0070
EPSS Percentile 71.6%

Classification

CWE
CWE-362
Status draft

Affected Products (3)

ibm/aix
ibm/aix
ibm/aix

Timeline

Published Dec 31, 2004
Tracked Since Feb 18, 2026