PT-2007-3872 · Hewlett Packard · Hp Tru64 Unix

Published

2007-05-09

·

Updated

2018-10-16

·

CVE-2007-2553

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions HP Tru64 UNIX versions 5.1A PK6, 5.1B-3, 5.1B-4
Description The issue allows local users to gain privileges by providing a large amount of data in the environment. This can be achieved by setting a long environment variable.
Recommendations For HP Tru64 UNIX version 5.1A PK6, consider restricting environment variable lengths to prevent exploitation. For HP Tru64 UNIX versions 5.1B-3 and 5.1B-4, limit the amount of data that can be passed via environment variables to minimize the risk of privilege escalation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2553

Affected Products

Hp Tru64 Unix