PT-2003-2054 · Hewlett Packard · Hp-Ux

Publicado

2003-12-31

·

Atualizado

2017-10-11

·

CVE-2003-1099

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions HP-UX versions B.11.00, B.11.04, B.11.11
Description The issue allows local users to cause a denial of service and possibly execute arbitrary code via a symlink attack, as temporary files are created with predictable names in /tmp.
Recommendations For HP-UX versions B.11.00, B.11.04, B.11.11, consider restricting access to the /tmp directory to minimize the risk of exploitation. As a temporary workaround, avoid using the shar command until a patch is available. Restrict access to the affected system to prevent local users from exploiting the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-1099

Produtos afetados

Hp-Ux