Executive brief
A vulnerability exists in the subnetconfig utility within older versions of the HP-UX operating system. This utility is responsible for configuring network subnets on the system. A local user with standard access could exploit this flaw to gain elevated administrative privileges, potentially allowing them to view sensitive data or modify system settings.
Technical details
A privilege escalation vulnerability exists in the subnetconfig utility of HP-UX versions 9.0 and 9.01. The flaw allows a local, unprivileged attacker to execute the utility in a way that grants elevated system privileges. While the specific root cause (such as a buffer overflow or insecure file handling) is not detailed in the legacy advisory, the impact is a compromise of confidentiality, integrity, and availability. This is a local attack requiring prior access to the system. Patches were historically made available by the vendor under advisory HPSBUX9402-003.
Affected products
- HP HP-UX 9.0, 9.01
Timeline
- 1994-02-07: disclosed: Initial publication date