Junglewise Threat Intelligence

CVE-1999-0325: HP HP-UX symlink vulnerability in vhe_u_mnt

CVE-1999-0325 · Severity: high · CVSS 7.2 · Published 1995-12-01

Technologies: Hp-Ux. Vendors: Hp.

Executive brief

A vulnerability in the vhe_u_mnt utility within the HP-UX operating system allows local users to create files with administrative (root) privileges. By exploiting this flaw, an attacker who already has basic access to the system can gain full control over the server, potentially leading to data theft, system disruption, or permanent compromise of the environment.

Technical details

The vhe_u_mnt utility in HP-UX is vulnerable to a symlink attack. A local attacker can create a symbolic link at a predictable file path used by the program, pointing to a sensitive system file or a new file location. When vhe_u_mnt is executed, it follows the symlink and performs file operations with elevated privileges, allowing the attacker to create or modify files owned by root. This can be leveraged to achieve full local privilege escalation. The vulnerability was originally addressed in HP security advisory HPSBUX9406-013.

Affected products

  • HP HP-UX

Timeline

  • 1995-12-01: disclosed: Initial publication date in NVD

References

Related threats