Junglewise Threat Intelligence

CVE-1999-1160: HP HP-UX privilege escalation in ftpd and kftpd

CVE-1999-1160 · Severity: critical · CVSS 10 · Published 1997-02-02

Technologies: Hp-Ux. Vendors: Hp.

Executive brief

A vulnerability in the FTP service of HP-UX systems allows both local and remote users to gain full administrative (root) control. This affects the standard ftpd and kftpd components used for file transfers. An attacker could exploit this to access, modify, or delete any file on the system, potentially leading to a complete compromise of the server and its data.

Technical details

A vulnerability exists in the ftpd and kftpd executables on HP-UX 9.x and 10.x. The flaw allows both regular and anonymous FTP users to bypass security restrictions and access files with root privileges. The attack can be initiated over the network without prior authentication if anonymous FTP is enabled, or locally by an authenticated user. Successful exploitation results in complete system compromise (Full Confidentiality, Integrity, and Availability impact). HP released patches PHNE_10008, PHNE_10009, PHNE_10010, and PHNE_10011 to address this issue in 1997.

Affected products

  • HP HP-UX 9.x, 10.x

Timeline

  • 1997-02-02: disclosed
  • 1997-02-19: advisory: HP Security Bulletin HPSBUX9702-055 released
  • 1997-02-19: patched

References

Related threats