Vulnerability of AIX: privilege increase with

Synthesis of the vulnerability 

A local attacker can increase his privileges using script.
Vulnerable systems: AIX.
Severity of this threat: 2/4.
Creation date: 14/11/2005.
Références of this weakness: BID-1539, IY78800, IY78801, IY78926, VIGILANCE-VUL-5354.

Description of the vulnerability 

Script /usr/lpp/diagnostics/bin/ contains one vulnerability. Its technical details are unknown.

This vulnerability could be related to usage of shell commands without using their full absolute path.
This security threat impacts software or systems such as AIX.

Our Vigil@nce team determined that the severity of this computer weakness note is medium.

The trust level is of type confirmed by the editor, with an origin of user account.

An attacker with a expert ability can exploit this computer threat alert.

Solutions for this threat 

AIX: APAR and ifix for
An ifix is available:
An APAR will be available on January 2006:
  AIX 5.1 : IY78926
  AIX 5.2 : IY78800
  AIX 5.3 : IY78801
A workaround is to remove suid bit:
  chmod 500 /usr/lpp/diagnostics/bin/diagela_exec
