Executive brief
A vulnerability in the movemail utility on HP-UX 10.20 systems allows local users to gain unauthorized elevated privileges. Movemail is a tool used to move mail from a central spool to a user's personal mailbox. An attacker with existing access to the system could exploit incorrect file permissions to compromise the integrity of the system or access sensitive data.
Technical details
The movemail utility in HP-UX 10.20 was distributed with insecure file permissions (typically involving setuid or setgid bits or overly permissive write access). This vulnerability allows a local attacker to exploit the utility to gain the privileges of the file owner or group, which is often 'mail' or 'root'. The attack requires local shell access but no special authentication beyond a standard user account. Successful exploitation results in a loss of confidentiality, integrity, and availability. HP released a patch (HPSBUX9701-047) to address this issue by correcting the file permissions.
Affected products
- HP HP-UX 10.20
Timeline
- 1997-01-06: disclosed: Initial publication of the vulnerability details.
- 1997-01-06: advisory: HP released security advisory HPSBUX9701-047.