Junglewise Threat Intelligence

CVE-1999-1133: HP HP-UX privilege escalation in X Windows utilities

CVE-1999-1133 · Severity: medium · CVSS 4.6 · Published 1997-09-01

Technologies: Hp-Ux. Vendors: Hp.

Executive brief

A vulnerability in HP-UX operating systems running X Windows allows local users to gain unauthorized elevated privileges. By exploiting specific system utilities like file managers and text editors, a user who already has basic access to the system can bypass authentication and perform actions with higher-level permissions. This could lead to unauthorized data access or full control over the affected workstation or server.

Technical details

A privilege escalation vulnerability exists in HP-UX 9.x and 10.x within the X Windows environment. The issue stems from several SetUID/SetGID utilities, specifically vuefile, vuepad, dtfile, and dtpad, which fail to properly authenticate users or validate environment variables, allowing a local attacker to execute commands with the privileges of the application owner (often root). This is closely related to underlying buffer overflows in the libXt and Motif libraries (X11R5/X11R6). Attackers with local shell access can exploit these binaries to gain administrative control. HP released several patches (e.g., PHSS_11626, PHSS_11043) to address the library vulnerabilities and updated the affected VUE/CDE components.

Affected products

  • HP HP-UX 9.x, 10.x

Timeline

  • 1997-09-01: advisory: Initial NVD publication date
  • 1997-09-09: disclosed: HP Security Bulletin HPSBUX9709-069 released via Bugtraq

References

Related threats