PT-2007-3872 · Hewlett Packard · Hp Tru64 Unix
Published
2007-05-09
·
Updated
2018-10-16
·
CVE-2007-2553
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
HP Tru64 UNIX versions 5.1A PK6, 5.1B-3, 5.1B-4
Description
The issue allows local users to gain privileges by providing a large amount of data in the environment. This can be achieved by setting a long environment variable.
Recommendations
For HP Tru64 UNIX version 5.1A PK6, consider restricting environment variable lengths to prevent exploitation.
For HP Tru64 UNIX versions 5.1B-3 and 5.1B-4, limit the amount of data that can be passed via environment variables to minimize the risk of privilege escalation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hp Tru64 Unix