Executive brief
A vulnerability in the software installation and modification tools of HP-UX systems allows local users to gain full administrative control. By exploiting flaws in how these tools handle files, an attacker with basic access to the system can overwrite critical system files. This can lead to a complete takeover of the server, compromising all data and services hosted on the machine.
Technical details
The vulnerability exists within the swinstall and swmodify utilities, which are part of the Software Distributor (SD-UX) package in HP-UX. These commands fail to properly validate file operations, allowing a local, unprivileged user to create or overwrite arbitrary files on the system. By targeting sensitive system files (such as /etc/passwd or system binaries), an attacker can escalate their privileges to root. This is a local privilege escalation vulnerability requiring shell access but no special permissions. Patch information is generally found in legacy HP security bulletins (e.g., HPSBUX9701-057).
Affected products
- HP HP-UX SD-UX package HP-UX 10.x and earlier
Timeline
- 1996-12-19: disclosed: Initial public disclosure date