PT-2007-3872 · Hewlett Packard · Hp Tru64 Unix

Publicado

2007-05-09

·

Atualizado

2018-10-16

·

CVE-2007-2553

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions HP Tru64 UNIX versions 5.1A PK6, 5.1B-3, 5.1B-4
Description The issue allows local users to gain privileges by providing a large amount of data in the environment. This can be achieved by setting a long environment variable.
Recommendations For HP Tru64 UNIX version 5.1A PK6, consider restricting environment variable lengths to prevent exploitation. For HP Tru64 UNIX versions 5.1B-3 and 5.1B-4, limit the amount of data that can be passed via environment variables to minimize the risk of privilege escalation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2553

Produtos afetados

Hp Tru64 Unix