PT-1996-1049 · Hewlett Packard · Hp-Ux
Published
1996-12-13
·
Updated
2017-07-11
·
CVE-1999-1089
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
HP-UX versions 9.X through 10.20
Description
A buffer overflow issue exists in the chfn command, allowing local users to gain privileges by providing a long command line argument.
Recommendations
For HP-UX versions 9.X through 10.20, consider restricting access to the chfn command until a patch is available. As a temporary workaround, avoid using long command line arguments with the chfn command to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hp-Ux