CVE-1999-0325: High severity HPE HP-UX vulnerability

Published Dec 1, 1995
·
Updated

vheumnt program in HP-UX allows local users to create root files through symlinks.

Affected Software

2 affected components
HPE HP-UX=8
HPE HP-UX=9

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove vhe_u_mnt (HP-UX) from your environment.

    Uninstall or remove the vhe_u_mnt program from systems where it is not required to eliminate the vulnerability that allows local users to create root files via symlinks.

  2. Configuration

    Change ownership and permissions of the vhe_u_mnt binary so only root can execute it (for example, set owner to root and remove execute permission for non-root users) to prevent local users from exploiting symlinks.

    vhe_u_mnt (HP-UX) file execution permissions = restrict to root only (e.g., root ownership and no execute permission for other users)
  3. Compensating control

    If removal or permission changes are not possible immediately, restrict which local accounts can access or execute vhe_u_mnt using filesystem ACLs or other host-level access controls so unprivileged users cannot run the program.

Event History

Dec 1, 1995
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Sep 29, 1999
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-0325?

CVE-1999-0325 is considered a high severity vulnerability due to its potential to allow local users to create root files.

2

How does CVE-1999-0325 impact HP-UX systems?

CVE-1999-0325 allows local users on HP-UX systems to escalate their privileges by creating root-level files through symlinks.

3

How do I fix CVE-1999-0325?

To fix CVE-1999-0325, apply the relevant patches provided for HP-UX versions 8 and 9.

4

Who is affected by CVE-1999-0325?

CVE-1999-0325 affects local users on HP-UX operating systems, specifically versions 8 and 9.

5

Is there a workaround for CVE-1999-0325?

A recommended workaround for CVE-1999-0325 includes restricting local user access to the vhe_u_mnt program to minimize exploitation risks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203