Junglewise Threat Intelligence

CVE-1999-0308: HP HP-UX arbitrary file modification in gwind

CVE-1999-0308 · Severity: medium · CVSS 4.6 · Published 1996-10-01

Technologies: Hp-Ux. Vendors: Hp.

Executive brief

A vulnerability in the gwind utility on HP-UX systems allows local users to modify files they should not have access to. This could allow an attacker with a standard user account to alter system configuration files or sensitive data, potentially leading to a full system compromise. The issue affects older HP-UX environments where this specific program is installed.

Technical details

The gwind program in HP-UX fails to properly restrict file access permissions, leading to an arbitrary file modification vulnerability. A local attacker with access to the system can exploit this flaw to write to or modify files that are normally restricted to higher-privileged users or the root account. This is likely due to insecure handling of file paths or improper privilege dropping within the gwind utility. Successful exploitation can result in unauthorized data modification, privilege escalation, or system instability. The vulnerability is addressed in HP security advisory HPSBUX9410-018.

Affected products

  • HP HP-UX

Timeline

  • 1996-10-01: disclosed
  • 1996-10-01: advisory

References

Related threats