PT-2003-2052 · Hewlett Packard · Hp-Ux

Davide Del Vecchio

·

Published

2003-12-31

·

Updated

2017-10-11

·

CVE-2003-1097

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions HP-UX versions B.10.20 through B.11.04
Description A buffer overflow issue exists in the rexec function on HP-UX. This issue may allow local users to gain privileges when the function is setuid root, by providing a long -l option.
Recommendations For HP-UX versions B.10.20 through B.11.04, consider restricting the use of the rexec function when setuid root to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-1097

Affected Products

Hp-Ux