PT-2006-2264 · Hewlett Packard · Hp-Ux
Published
2006-03-17
·
Updated
2017-10-11
·
CVE-2006-1248
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
HP-UX versions B.11.00 through B.11.23
Description
The issue is related to the usermod command in HP-UX. When run with certain options that involve creating a new home directory, it might change the ownership of all directories and files under the new directory. This could result in less secure permissions than intended.
Recommendations
For HP-UX versions B.11.00 through B.11.23, consider restricting the use of the usermod command with options that involve creating a new home directory until a fix is available. As a temporary workaround, manually verify and adjust the permissions of newly created home directories and their contents to ensure they match the intended security settings.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hp-Ux