>> IBM AIX "man" Untrusted Binaries Path Privilege Escalation Vulnerability
Title : IBM AIX "man" Untrusted Binaries Path Privilege Escalation Vulnerability VUPEN ID : VUPEN/ADV-2008-0805 CVE ID : CVE-2008-1274
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2008-03-10
Technical Description
A vulnerability has been identified in IBM AIX, which could be exploited by local attackers to obtain elevated privileges. This issue is caused by an error in the "/usr/bin/man" utility that does not properly call binaries using full paths, which could be exploited by malicious users to execute arbitrary code by tricking a user into running "man" in a directory containing a specially crafted binary.