Junglewise Threat Intelligence

CVE-1999-1145: HP GlancePlus privilege escalation in Glance programs

CVE-1999-1145 · Severity: high · CVSS 7.2 · Published 1997-01-07

Vendors: Hp.

Executive brief

A security vulnerability exists in the GlancePlus performance monitoring tool on older HP-UX systems. This flaw allows a person with basic access to the computer to view restricted files and gain administrative control over the system. This could lead to the theft of sensitive data or a complete takeover of the affected server.

Technical details

A privilege escalation vulnerability exists in the Glance utility of HP GlancePlus on HP-UX 10.20 and earlier. The flaw likely stems from insecure handling of file operations or environment variables within the Glance binaries, which typically run with elevated permissions. A local attacker with standard user access can exploit this to read or write to arbitrary files on the system, ultimately leading to full root access. The vulnerability is exploitable locally without prior authentication beyond initial system access. Patches were historically made available via HP security advisories.

Affected products

  • HP GlancePlus HP-UX 10.20 and earlier

Timeline

  • 1997-01-07: disclosed: Initial publication date

References

Related threats