Executive brief
A security vulnerability exists in the hpterm terminal emulator on HP-UX 10.20 systems. This flaw allows a person who already has basic access to the computer to gain higher-level administrative privileges. This could lead to unauthorized access to sensitive data or the ability to modify system settings.
Technical details
A vulnerability in the hpterm terminal emulator on HP-UX 10.20 allows local users to escalate their privileges. The flaw likely stems from improper handling of environment variables or file permissions within the setuid/setgid hpterm binary, a common issue in legacy Unix terminal emulators. An attacker with local shell access can exploit this to execute commands with the privileges of the hpterm process, typically leading to root or group-level access. HP released advisory HPSBUX9903-093 to address this issue.
Affected products
- HP HP-UX 10.20 10.20
Timeline
- 1994-06-01: disclosed: Initial publication date
- 1999-03-01: advisory: HP Security Bulletin HPSBUX9903-093 released