CVE-1999-0311: High severity HPE HP-UX vulnerability
fpkg2swpk in HP-UX allows local users to gain root access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
HP-UX/fpkg2swpkfrom your environment.Remove or disable the fpkg2swpk utility on affected HP-UX systems (for example, uninstall the package, remove the binary, or otherwise prevent its execution) until a vendor-supplied fix is available.
- Compensating control
Restrict local user access to affected HP-UX systems: limit interactive logins to trusted administrators, enforce least-privilege accounts, and prevent untrusted/local users from executing system administration utilities.
- Operational
Monitor affected systems for signs of exploitation. If compromise is suspected, assume root compromise and perform incident response actions such as isolating the host, restoring from known-good backups, and rotating credentials. Track vendor advisories and apply the vendor-supplied patch as soon as it is released.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0311?
CVE-1999-0311 is considered critical as it allows local users to gain root access on HP-UX systems.
How do I fix CVE-1999-0311?
To fix CVE-1999-0311, apply the appropriate security patch provided by HP for HP-UX version 10.
Who is affected by CVE-1999-0311?
CVE-1999-0311 affects local users on HP-UX version 10 systems.
What are the implications of CVE-1999-0311?
The implications of CVE-1999-0311 include unauthorized privilege escalation, leading to a total compromise of the system.
When was CVE-1999-0311 discovered?
CVE-1999-0311 was discovered in 1999 and has been a known vulnerability for over two decades.