Junglewise Threat Intelligence

CVE-1999-0962: HP HP-UX buffer overflow in passwd command

CVE-1999-0962 · Severity: high · CVSS 7.2 · Published 1997-05-14

Technologies: Hp-Ux. Vendors: Hp.

Executive brief

A security vulnerability exists in the password management utility of the HP-UX operating system. This flaw allows a person who already has basic access to the system to gain full administrative (root) control. Such an exploit could lead to a total compromise of the server, including unauthorized access to all data and the ability to disrupt operations.

Technical details

A buffer overflow vulnerability exists within the 'passwd' executable in HP-UX. The flaw is triggered by providing an overly long or malformed string to a specific command-line option, which fails to perform adequate bounds checking. Because the 'passwd' utility typically runs with elevated (SetUID root) privileges to modify system authentication files, a successful exploit allows a local, unprivileged attacker to execute arbitrary code with root authority. This is a classic local privilege escalation (LPE) vulnerability. HP released advisory HPSBUX9701-045 to address this issue.

Affected products

  • HP HP-UX

Timeline

  • 1997-05-14: advisory: NVD Published Date
  • 1997-01-01: advisory: HP Advisory HPSBUX9701-045 issued (approximate date based on ID)

References

Related threats