uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier trusts the user-supplied -uv.install command line option to find and execute the uv.install program, which allows local users to gain privileges by providing a pathname that is under control of the user.
References
Link | Resource |
---|---|
http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0026.html | Exploit Vendor Advisory |
http://marc.info/?l=bugtraq&m=105838948002337&w=2 |
Configurations
Information
Published : 2003-08-17 21:00
Updated : 2016-10-17 19:35
NVD link : CVE-2003-0579
Mitre link : CVE-2003-0579
JSON object : View
CWE
Products Affected
ibm
- u2_universe