First published: Wed Feb 10 1999(Updated: )
rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HPE HP-UX | =10.01 | |
HPE HP-UX | =11.00 | |
HPE HP-UX | =10.20 | |
HPE HP-UX | =10.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0353 is considered a critical vulnerability due to its potential for granting remote root access.
To fix CVE-1999-0353, you should update the rpc.pcnfsd to a patched version provided by HP for affected HP-UX versions.
CVE-1999-0353 affects HP-UX versions 10.01, 10.10, 10.20, and 11.00.
Exploiting CVE-1999-0353 allows attackers to gain remote root access to the affected HP-UX systems.
A possible workaround for CVE-1999-0353 includes restricting access to the printer spool directory and disabling rpc.pcnfsd if not needed.