Junglewise Threat Intelligence

CVE-1999-1238: HP HP-UX privilege escalation in CORE-DIAG message catalog

CVE-1999-1238 · Severity: medium · CVSS 4.6 · Published 1994-09-21

Technologies: Hp-Ux. Vendors: Hp.

Executive brief

A security vulnerability exists in the CORE-DIAG component of the HP-UX operating system's message catalog. This flaw allows a person who already has basic access to the system to gain higher-level administrative privileges. This could lead to unauthorized access to sensitive data or full control over the affected server.

Technical details

A privilege escalation vulnerability exists in the CORE-DIAG fileset within the HP-UX message catalog. The flaw resides in how the operating system handles diagnostic message files, which can be manipulated by local users to execute commands or modify files with elevated permissions. An attacker with local shell access can exploit this vulnerability to bypass security restrictions and gain root-level privileges. This issue affects HP-UX versions 9.05 and earlier. HP released a patch (referenced in historical advisories) to address this issue by correcting the handling of the message catalog files.

Affected products

  • HP HP-UX 9.05 and earlier

Timeline

  • 1994-09-21: disclosed: Initial publication date

References

Related threats