search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Hewlett Packard HP-UX pcltotiff is installed with insecure permissions

Vulnerability Note VU#314776

Original Release Date: 2001-08-15 | Last Revised: 2001-08-17

Overview

The utility pcltotiff is installed with insecure permissions on some Hewlett Packard systems.

Description

The HP utility pcltotiff is installed with sgid bin permissions in order to read files in /usr/lib/X11/fonts/ifo.st/typefaces/. This gives more permissions to pcltotiff than are required. For more information, see HP Security Bulletin HPSBUX0104-149.

Impact

The complete impact of this vulnerability is not yet known. Hewlett Packard lists the impact as "Denial of service," but it is unclear why.

Solution

Change the permissions on the file as described in HP bulletin.

Vendor Information

314776
 

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

This document was written by Shawn V. Hernan.

Other Information

CVE IDs: CVE-2001-0488
Severity Metric: 2.53
Date Public: 2001-04-24
Date First Published: 2001-08-15
Date Last Updated: 2001-08-17 21:25 UTC
Document Revision: 7

Sponsored by CISA.