CVE-1999-0324: High severity HPE HP-UX vulnerability
ppl program in HP-UX allows local users to create root files through symlinks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
HP-UX/pplfrom your environment.Uninstall or disable the 'ppl' program on affected HP-UX systems if it is not required to prevent local users from creating root-owned files via symlink attacks.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0324?
CVE-1999-0324 is considered a critical vulnerability due to its potential to allow local users to gain root access.
How do I fix CVE-1999-0324?
To fix CVE-1999-0324, ensure that the permissions of the ppl program are properly set to prevent unauthorized use.
Which versions of HP-UX are affected by CVE-1999-0324?
CVE-1999-0324 affects HP-UX versions 9.0, 10.00, 10.01, 10.10, and 10.20.
Who is impacted by CVE-1999-0324?
Local users with access to the HP-UX system are impacted by CVE-1999-0324 if proper security measures are not in place.
Is there a workaround for CVE-1999-0324?
A temporary workaround for CVE-1999-0324 includes restricting user permissions and monitoring the use of the ppl program.