PT-2001-2648 · Hewlett Packard · Hp-Ux

Published

2001-12-31

·

Updated

2017-10-12

·

CVE-2001-1564

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions HP-UX versions 10.01, 10.10, 10.20, 10.24, 11.00, 11.04, 11.11
Description The issue is related to the setrlimit function in HP-UX, which does not properly enforce core file size on processes after setuid or setgid privileges are dropped. This could allow local users to cause a denial of service by exhausting available disk space.
Recommendations For HP-UX versions 10.01, 10.10, 10.20, 10.24, 11.00, 11.04, 11.11, consider restricting disk space availability to prevent exhaustion. As a temporary workaround, consider implementing strict disk quotas to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-1564

Affected Products

Hp-Ux