lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing the -f option, which allows local users to read one line of arbitrary files.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ibm aix 5.2 |
||
ibm aix 5.3 |