search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Hewlett-Packard HP-UX Software Distributor (SD-UX) contains vulnerability permitting privilege escalation

Vulnerability Note VU#712632

Original Release Date: 2001-09-26 | Last Revised: 2001-09-26

Overview

HP9000 Series 700/800 running HP-UX releases 10.01, 10.10, 10.20 and 11.00 are affected by a buffer overflow in Hewlett-Packard's HP-UX Software Distributor (SD-UX). A local user can exploit this vulnerability to gain elevated privileges.

Description

Several applications in SD-UX contain buffer overflows. SWVERIFY is one such component that is vulnerable. A local user can exploit this vulnerability to gain elevated privileges. An exploit is public.

Impact

A local user can gain a shell with the privileges of the SD-UX component exploited.

Solution

Apply the patches as described in Hewlett-Packard's Security Bulletin #0143.

Vendor Information

712632
 

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

Our thanks to Hewlett-Packard for aiding in the identification of this vulnerability.

This document was written by Jason Rafail.

Other Information

CVE IDs: CVE-2001-0979
Severity Metric: 6.68
Date Public: 2001-02-28
Date First Published: 2001-09-26
Date Last Updated: 2001-09-26 15:07 UTC
Document Revision: 4

Sponsored by CISA.