Executive brief
A security vulnerability exists in the HP-UX operating system's utility used for switching user group identities. A local attacker can exploit this flaw to gain unauthorized administrative control over the system. This could lead to a complete compromise of the server, including the theft of sensitive data or the disruption of business operations.
Technical details
A buffer overflow vulnerability exists within the 'newgrp' executable in HP-UX. The 'newgrp' utility is typically a setuid-root program used to change a user's current group ID during a login session. By providing specially crafted, overly long input to the program, a local attacker can trigger a memory corruption event. Because the utility runs with elevated privileges, successful exploitation allows the attacker to execute arbitrary code with root-level permissions.
Affected products
- HP HP-UX
Timeline
- 1996-12-01: disclosed