CVE-1999-0336: Buffer Overflow
Buffer overflow in mstm in HP-UX allows local users to gain root access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
HPE HP-UX mstmfrom your environment.Uninstall or remove the mstm component from systems where it is not required.
- Configuration
Disable or stop the mstm service/binary on affected HP-UX systems until a vendor fix is available.
mstm (HP-UX) enabled = false - Compensating control
Restrict local user access and privileges on affected systems (limit interactive logins, enforce least privilege) to reduce the risk of local users exploiting the vulnerability to gain root.
- Operational
Monitor system and audit logs for signs of local privilege escalation and apply any vendor-supplied patches or updates for HP-UX/mstm as soon as they become available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0336?
CVE-1999-0336 has a high severity rating due to the potential for local users to gain root access.
How do I fix CVE-1999-0336?
To fix CVE-1999-0336, it is recommended to apply patches provided by HPE for HP-UX version 10.
Who is affected by CVE-1999-0336?
CVE-1999-0336 affects local users on systems running HP-UX version 10.
What are the risks associated with CVE-1999-0336?
The risks of CVE-1999-0336 include unauthorized access to system resources and potential compromise of system integrity.
Is CVE-1999-0336 still a threat today?
While CVE-1999-0336 is an older vulnerability, systems that have not been updated may still be at risk if running HP-UX version 10.