search menu icon-carat-right cmu-wordmark

CERT Coordination Center

HP-UX CDE library libDtSvc contains unspecified buffer overflow

Vulnerability Note VU#406406

Original Release Date: 2004-03-23 | Last Revised: 2006-06-13

Overview

CDE, the default X Windows environment in HP-UX, ships with a libraray called libDtSvc. It has a locally-exploitable buffer overflow in some versions.

Description

Please see HP Security Bulletin HPSBUX0401-308 SSRT3492 for more details.

Impact

A local user may be able to gain root-level access.

Solution

Apply the appropriate vendor patch.

Vendor Information

406406
 

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

Thanks to the HP IT Resource Center for reporting this vulnerability.

This document was written by Jeffrey S. Havrilla

Other Information

CVE IDs: CVE-2004-1764
Severity Metric: 7.13
Date Public: 2004-01-14
Date First Published: 2004-03-23
Date Last Updated: 2006-06-13 15:40 UTC
Document Revision: 3

Sponsored by CISA.