Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Untrusted search path vulnerability in the mkvg command in IBM AIX 5.2 and 5.3 allows local users to gain privileges by modifying the path to point to a malicious (1) chdev, (2) mkboot, (3) varyonvg, or (4) varyoffvg program.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM AIX mkvg工具程序调用本地权限提升漏洞
Vulnerability Description
IBM AIX是一款商业性质的UNIX操作系统。 AIX的mkvg工具在处理外部程序调用时存在漏洞,本地攻击者可能利用此漏洞提升自己的权限。 mkvg工具在调用chdev、mkboot、varyonvg和varyoffvg工具时没有使用绝对路径名,允许system组中的本地用户以root用户权限执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A