Junglewise Threat Intelligence

CVE-1999-1251: HP HP-UX denial of service in direct audio user space code

CVE-1999-1251 · Severity: low · CVSS 2.1 · Published 1996-12-24

Technologies: Hp-Ux. Vendors: Hp.

Executive brief

A vulnerability in the audio management software of HP-UX systems allows a local user to disrupt the system's audio services. This could lead to a denial of service where the audio functionality becomes unavailable to other users or applications. While it does not allow for data theft, it can impact operations that rely on sound or system stability.

Technical details

A denial of service vulnerability exists in the direct audio user space code of HP-UX versions 10.10 and 10.20. The flaw allows a local attacker with system access to trigger a condition that crashes or hangs the audio subsystem. The attack vector is local, requiring the user to already have an account or access to the machine. Successful exploitation results in a loss of availability for audio services, though it does not appear to facilitate privilege escalation or data disclosure. HP released an advisory (HPSBUX9701-056) regarding this issue in 1996.

Affected products

  • HP HP-UX 10.10, 10.20

Timeline

  • 1996-12-24: disclosed: Initial publication of the vulnerability details.
  • 1996-12-24: advisory: NVD published date.

References

Related threats