Junglewise Threat Intelligence

CVE-1999-1161: HP HP-UX privilege escalation in ppl via core dump

CVE-1999-1161 · Severity: high · CVSS 7.2 · Published 1996-11-03

Technologies: Hp-Ux. Vendors: Hp.

Executive brief

A vulnerability in the 'ppl' utility on older HP-UX systems allows a local user to gain full administrative (root) control. By forcing the program to crash and create a memory dump file in a specific location, an attacker can overwrite system configuration files. This allows them to bypass security restrictions and take over the entire server.

Technical details

The 'ppl' utility in HP-UX 10.x and earlier is vulnerable to a privilege escalation attack via insecure core dump handling. A local attacker can create a symbolic link from a core file in the current directory to a sensitive system file, such as ~root/.rhosts. By providing a specially crafted, overly long string to the '-o' flag, the attacker triggers a buffer overflow that causes the program to crash. Because the program may be running with elevated privileges or within a world-writable directory, the resulting core dump (containing attacker-controlled data) overwrites the linked file, allowing the attacker to gain root access via services like remsh.

Affected products

  • HP HP-UX 10.x and earlier

Timeline

  • 1996-11-03: disclosed: Initial public disclosure on Bugtraq
  • 1996-11-03: advisory: NVD published date

References

Related threats