Executive brief
A vulnerability in the HP-UX operating system allows standard users to gain full administrative control over the server. By exploiting a flaw in the vgdisplay utility, which is used to manage disk storage, a local attacker can bypass security restrictions to access sensitive data or disrupt operations. This could lead to a complete compromise of the affected system's integrity and confidentiality.
Technical details
A privilege escalation vulnerability exists in the HP-UX 'vgdisplay' utility, a component of the Logical Volume Manager (LVM). The flaw allows a local, unprivileged user to execute commands or manipulate system files with root-level permissions. While the specific mechanism (such as a buffer overflow or insecure environment variable handling) is not detailed in the legacy advisory, the impact is a full compromise of the local host. This issue affects older versions of the HP-UX operating system and was addressed in HP security advisory HPSBUX9702-056.
Affected products
- HP HP-UX
Timeline
- 1997-02-01: disclosed: Initial publication of the vulnerability.
- 1997-02-01: advisory: HP released advisory HPSBUX9702-056.