Executive brief
A security vulnerability exists in the Glance and gpm performance monitoring tools within HP-UX systems. A local user with standard access can exploit these programs to read or modify sensitive system files they should not be able to reach. This could allow an attacker to take full control of the server or access confidential data.
Technical details
The Glance and gpm utilities in HP-UX GlancePlus (version 9.x and earlier) contain a vulnerability that allows for local privilege escalation. The flaw likely stems from insecure file handling or improper permission management within these setuid/privileged binaries. A local attacker can leverage this to access arbitrary files with elevated permissions, potentially leading to a full system compromise. The vulnerability is exploitable by any user with local shell access to the affected system. Patch information is referenced in historical security advisories from the vendor.
Affected products
- HP GlancePlus HP-UX 9.x and earlier
Timeline
- 1994-05-04: disclosed: Initial publication date