PT-2006-2264 · Hewlett Packard · Hp-Ux

Published

2006-03-17

·

Updated

2017-10-11

·

CVE-2006-1248

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions HP-UX versions B.11.00 through B.11.23
Description The issue is related to the usermod command in HP-UX. When run with certain options that involve creating a new home directory, it might change the ownership of all directories and files under the new directory. This could result in less secure permissions than intended.
Recommendations For HP-UX versions B.11.00 through B.11.23, consider restricting the use of the usermod command with options that involve creating a new home directory until a fix is available. As a temporary workaround, manually verify and adjust the permissions of newly created home directories and their contents to ensure they match the intended security settings.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1248
HPSBUX02102

Affected Products

Hp-Ux