CVE-2006-4416

IBM AIX <5.3 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Untrusted search path vulnerability in the mkvg command in IBM AIX 5.2 and 5.3 allows local users to gain privileges by modifying the path to point to a malicious (1) chdev, (2) mkboot, (3) varyonvg, or (4) varyoffvg program.

References (12)

Core 12
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22106
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/29165
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016920
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/20197
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3389
Various Sources vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=isg1IY88737
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21620
Various Sources vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=isg1IY88722
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/19708
Various Sources vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=isg1IY88699
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3770
Various Sources x_refsource_confirm
ftp://aix.software.ibm.com/aix/efixes/security/README

Scores

EPSS 0.0042
EPSS Percentile 34.0%

Details

Status published
Products (3)
ibm/aix 5.1
ibm/aix 5.2
ibm/aix 5.3
Published Aug 28, 2006
Tracked Since Feb 18, 2026