search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Hewlett-Packard HP-UX newgrp command does not function properly

Vulnerability Note VU#249224

Original Release Date: 2001-05-01 | Last Revised: 2004-02-23

Overview

A security vulnerability exists in the newgrp command on certain Hewlett-Packard systems.

Description

HP9000 servers running HP-UX release 11.11 contain a security vulnerability allowing users to gain increased capability. No further details are available. See HP document HPSBUX0103-147.

Impact

The complete impact of this vulnerability is not yet known.

Solution

Apply a patch as described in the HP bulletin.

Vendor Information

249224
 

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

This document was written by Shawn V. Hernan.

Other Information

CVE IDs: None
Date Public: 2001-03-26
Date First Published: 2001-05-01
Date Last Updated: 2004-02-23 22:12 UTC
Document Revision: 6

Sponsored by CISA.