Executive brief
A security vulnerability exists in the mediainit utility within the HP-UX operating system. This program is used for initializing disk media. If exploited, a local user could potentially gain unauthorized access or interfere with system operations, compromising the integrity and confidentiality of the server.
Technical details
The mediainit utility in HP-UX contains an unspecified vulnerability that can be exploited by local users. Based on the CVSS v2 vector (AV:L/AC:L/Au:N/C:P/I:P/A:P), the flaw allows for a local attack with low complexity and no authentication required, resulting in partial impacts to confidentiality, integrity, and availability. This typically suggests a privilege escalation or insecure file handling issue common in legacy Unix utilities. HP released an advisory (HPSBUX9710-071) regarding this issue in 1997.
Affected products
- HP HP-UX
Timeline
- 1997-10-01: advisory: HP released security advisory HPSBUX9710-071
- 1997-10-01: disclosed