Junglewise Threat Intelligence

CVE-1999-0324: HP HP-UX symlink vulnerability in ppl program

CVE-1999-0324 · Severity: high · CVSS 7.2 · Published 1996-09-01

Technologies: Hp-Ux. Vendors: Hp.

Executive brief

A vulnerability in the HP-UX operating system's 'ppl' utility allows local users to create or overwrite files with root-level privileges. This could allow an unauthorized user to gain full control over the system or cause a complete service outage by corrupting critical system files. The issue stems from how the program handles temporary files, which can be redirected by a malicious user.

Technical details

The 'ppl' program in HP-UX is vulnerable to a symlink attack, a form of insecure temporary file handling. A local attacker can create a symbolic link from a file location the program intends to write to, pointing it instead toward a sensitive system file (such as /etc/passwd or system binaries). Because the program runs with elevated privileges, it follows the link and creates or overwrites the target file as the root user. This allows for local privilege escalation or arbitrary file creation. The vulnerability is addressed in HP security advisory HPSBUX9702-053.

Affected products

  • HP HP-UX

Timeline

  • 1996-09-01: disclosed
  • 1997-02-01: advisory: HP issued advisory HPSBUX9702-053

References

Related threats