Junglewise Threat Intelligence

CVE-1999-0309: HP HP-UX privilege escalation in vgdisplay

CVE-1999-0309 · Severity: high · CVSS 7.2 · Published 1997-02-01

Technologies: Hp-Ux. Vendors: Hp.

Executive brief

A vulnerability in the HP-UX operating system allows standard users to gain full administrative control over the server. By exploiting a flaw in the vgdisplay utility, which is used to manage disk storage, a local attacker can bypass security restrictions to access sensitive data or disrupt operations. This could lead to a complete compromise of the affected system's integrity and confidentiality.

Technical details

A privilege escalation vulnerability exists in the HP-UX 'vgdisplay' utility, a component of the Logical Volume Manager (LVM). The flaw allows a local, unprivileged user to execute commands or manipulate system files with root-level permissions. While the specific mechanism (such as a buffer overflow or insecure environment variable handling) is not detailed in the legacy advisory, the impact is a full compromise of the local host. This issue affects older versions of the HP-UX operating system and was addressed in HP security advisory HPSBUX9702-056.

Affected products

  • HP HP-UX

Timeline

  • 1997-02-01: disclosed: Initial publication of the vulnerability.
  • 1997-02-01: advisory: HP released advisory HPSBUX9702-056.

References

Related threats