Junglewise Threat Intelligence

CVE-1999-1242: HP HP-UX privilege escalation in subnetconfig

CVE-1999-1242 · Severity: medium · CVSS 4.6 · Published 1994-02-07

Technologies: Hp-Ux. Vendors: Hp.

Executive brief

A vulnerability exists in the subnetconfig utility within older versions of the HP-UX operating system. This utility is responsible for configuring network subnets on the system. A local user with standard access could exploit this flaw to gain elevated administrative privileges, potentially allowing them to view sensitive data or modify system settings.

Technical details

A privilege escalation vulnerability exists in the subnetconfig utility of HP-UX versions 9.0 and 9.01. The flaw allows a local, unprivileged attacker to execute the utility in a way that grants elevated system privileges. While the specific root cause (such as a buffer overflow or insecure file handling) is not detailed in the legacy advisory, the impact is a compromise of confidentiality, integrity, and availability. This is a local attack requiring prior access to the system. Patches were historically made available by the vendor under advisory HPSBUX9402-003.

Affected products

  • HP HP-UX 9.0, 9.01

Timeline

  • 1994-02-07: disclosed: Initial publication date

References

Related threats