Executive brief
A vulnerability in the fpkg2swpk utility within the HP-UX operating system allows a local user to gain full administrative (root) control over the system. This could lead to a complete compromise of the server, including unauthorized access to all data and the ability to disrupt critical operations. The issue affects older versions of the HP-UX environment.
Technical details
A local privilege escalation vulnerability exists in the fpkg2swpk utility on HP-UX systems. The flaw allows an unprivileged local user to execute commands or manipulate the system in a way that grants root-level permissions. While the specific vulnerability class (e.g., buffer overflow or insecure file handling) is not detailed in the legacy NVD record, the impact is a total loss of confidentiality, integrity, and availability. The attack requires local access to the system but no prior administrative privileges. HP addressed this issue in historical security bulletin HPSBUX9612-042.
Affected products
- HP HP-UX
Timeline
- 1996-11-01: disclosed
- 1996-11-01: advisory: NVD published date