[3681] in bugtraq

home help back first fref pref prev next nref lref last post

AIX lquerypv

daemon@ATHENA.MIT.EDU (Aleph One)
Mon Nov 25 21:21:48 1996

Date: 	Mon, 25 Nov 1996 09:50:18 -0600
Reply-To: Aleph One <aleph1@dfw.net>
From: Aleph One <aleph1@dfw.net>
To: Multiple recipients of list BUGTRAQ <BUGTRAQ@NETSPACE.ORG>

   Thanks to all that responded. To many to list! Here are the results:

AIX 3.2.X is reported as NOT vulnerable. The command does not have an -h
flag. But who knows it may have other problems. Poke it and see what you
can find.

AIX 4.1.X and 4.2 with all security PTF ARE vulnerable. The problem will
dump the first 256 bytes of any file you give it as an argument. It seems
IBM is aware of the problem. Quick fix: chmod u-s /usr/sbin/lquerypv

Aleph One / aleph1@dfw.net
http://underground.org/
KeyID 1024/948FD6B5
Fingerprint EE C9 E8 AA CB AF 09 61  8C 39 EA 47 A8 6A B8 01

home help back first fref pref prev next nref lref last post