VYPR
Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026

CVE-2004-2388

CVE-2004-2388

Description

rexecd for AIX 4.3.3 does not properly use a local copy of the pwd structure when calling getpwnam, which may cause the structure to be overwritten by the authenticate function and assign privileges to the wrong user.

Affected products

2
  • IBM/Aix2 versions
    cpe:2.3:o:ibm:aix:4.3.3:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:ibm:aix:4.3.3:*:*:*:*:*:*:*
    • (no CPE)range: = 4.3.3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.