CVE-2008-1599

IBM AIX 5.2, 5.3, 6.1 - Privilege Escalation via nddstat Environment Variable Handling

Title source: llm
STIX 2.1

Description

The nddstat programs on IBM AIX 5.2, 5.3, and 6.1 do not properly handle environment variables, which allows local users to gain privileges by invoking (1) atmstat, (2) entstat, (3) fddistat, (4) hdlcstat, or (5) tokstat.

References (10)

Core 10
Core References
Patch vendor-advisory x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=isg1IZ16975
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1019604
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5468
Patch vendor-advisory x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=isg1IZ17058
Patch vendor-advisory x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=isg1IZ17059
Patch vendor-advisory x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=isg1IZ16991
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0865

Scores

EPSS 0.0038
EPSS Percentile 30.6%

Details

CWE
CWE-264
Status published
Products (3)
ibm/aix 5.2
ibm/aix 5.3
ibm/aix 6.1
Published Mar 31, 2008
Tracked Since Feb 18, 2026