Junglewise Threat Intelligence

CVE-1999-1311: HP HP-UX authentication bypass in dtlogin and dtsession

CVE-1999-1311 · Severity: medium · CVSS 4.6 · Published 1997-01-07

Technologies: Hp-Ux. Vendors: Hp.

Executive brief

A security flaw in the login and session management components of HP-UX allows local users to bypass standard authentication procedures. This could allow an unauthorized person with physical or terminal access to the system to gain elevated administrative privileges. Such an exploit compromises the integrity of the operating system and the security of all data stored on the affected machine.

Technical details

A vulnerability exists within the Common Desktop Environment (CDE) components dtlogin and dtsession on HP-UX versions 10.10 and 10.20. The flaw allows a local attacker to bypass the standard authentication mechanism, potentially leading to unauthorized privilege escalation. Because the attack vector is local, the attacker must already have access to a local shell or physical console. Successful exploitation grants the attacker the ability to execute commands with the permissions of other users or the system itself. While specific technical root causes like buffer overflows or logic errors are not detailed in the legacy advisory, the impact is a confirmed authentication bypass.

Affected products

  • HP HP-UX 10.10, 10.20

Timeline

  • 1997-01-07: disclosed: Initial publication date

References

Related threats