Junglewise Threat Intelligence

CVE-1999-0311: HP HP-UX privilege escalation in fpkg2swpk

CVE-1999-0311 · Severity: high · CVSS 7.2 · Published 1996-11-01

Technologies: Hp-Ux. Vendors: Hp.

Executive brief

A vulnerability in the fpkg2swpk utility within the HP-UX operating system allows a local user to gain full administrative (root) control over the system. This could lead to a complete compromise of the server, including unauthorized access to all data and the ability to disrupt critical operations. The issue affects older versions of the HP-UX environment.

Technical details

A local privilege escalation vulnerability exists in the fpkg2swpk utility on HP-UX systems. The flaw allows an unprivileged local user to execute commands or manipulate the system in a way that grants root-level permissions. While the specific vulnerability class (e.g., buffer overflow or insecure file handling) is not detailed in the legacy NVD record, the impact is a total loss of confidentiality, integrity, and availability. The attack requires local access to the system but no prior administrative privileges. HP addressed this issue in historical security bulletin HPSBUX9612-042.

Affected products

  • HP HP-UX

Timeline

  • 1996-11-01: disclosed
  • 1996-11-01: advisory: NVD published date

References

Related threats