Executive brief
A vulnerability in the HP-UX 10.20 operating system fails to correctly process high-value user and group identification numbers. This flaw allows a local user already on the system to potentially bypass security restrictions and gain elevated administrative privileges. Such an exploit could lead to unauthorized access to sensitive data or full control over the affected server.
Technical details
The vulnerability is a privilege escalation flaw in HP-UX 10.20 caused by improper handling of large User IDs (UID) or Group IDs (GID) exceeding the value of 60000. When certain system programs encounter these high-value identifiers, they may fail to correctly enforce access controls or drop privileges. A local attacker with an account on the system can exploit this behavior to gain unauthorized elevated privileges. The issue is specific to the 10.20 release of the operating system and requires local access to the target machine.
Affected products
- HP HP-UX 10.20
Timeline
- 1997-07-31: disclosed: Initial publication date in NVD