PT-1996-1017 · Hewlett Packard · Hp-Ux
Published
1996-12-19
·
Updated
2022-08-17
·
CVE-1999-0127
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
HP-UX SD-UX package (affected versions not specified)
Description
The issue allows local users to create or overwrite arbitrary files, potentially gaining root access, by exploiting the swinstall and swmodify commands in the SD-UX package of HP-UX systems.
Recommendations
For the affected HP-UX SD-UX package, restrict access to the swinstall and swmodify commands to minimize the risk of exploitation.
As a temporary workaround, consider disabling the swinstall and swmodify commands until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hp-Ux