PT-1996-1017 · Hewlett Packard · Hp-Ux

Published

1996-12-19

·

Updated

2022-08-17

·

CVE-1999-0127

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions HP-UX SD-UX package (affected versions not specified)
Description The issue allows local users to create or overwrite arbitrary files, potentially gaining root access, by exploiting the swinstall and swmodify commands in the SD-UX package of HP-UX systems.
Recommendations For the affected HP-UX SD-UX package, restrict access to the swinstall and swmodify commands to minimize the risk of exploitation. As a temporary workaround, consider disabling the swinstall and swmodify commands until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-1999-0127

Affected Products

Hp-Ux