Executive brief
A vulnerability in the 'chsh' command on older HP-UX operating systems allows a local user to gain elevated system privileges. The 'chsh' utility is used by employees to change their default login shell. An attacker with a standard user account could exploit this flaw to take full control of the server, potentially leading to the theft of sensitive data or disruption of operations.
Technical details
A privilege escalation vulnerability exists in the 'chsh' (change shell) utility within HP-UX versions 9.X through 10.20. The flaw resides in the handling of user input or environment variables by the setuid-root executable, allowing a local, unprivileged user to execute arbitrary code or manipulate system files with root authority. An attacker must have local shell access to the system to execute the command. Successful exploitation results in a complete compromise of the host's confidentiality, integrity, and availability. Patches were historically made available by the vendor to address this issue.
Affected products
- HP HP-UX 9.X through 10.20
Timeline
- 1997-01-09: disclosed: Initial publication date