CVE-1999-0690: High severity CDE CDE vulnerability
HP CDE program includes the current directory in root's PATH variable.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Remove any reference to the current directory ('.' or an empty PATH entry) from root's PATH as set by the HP CDE program. Update the HP CDE/root startup configuration so that the current directory is not included in root's PATH variable.
HP CDE (root environment) PATH = no current-directory entries (no '.' or empty entry)
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0690?
CVE-1999-0690 has been classified as a medium severity vulnerability due to its potential for local privilege escalation.
How do I fix CVE-1999-0690?
To fix CVE-1999-0690, you should remove the current directory from the root's PATH variable in the system configuration.
What are the potential impacts of CVE-1999-0690?
The potential impacts of CVE-1999-0690 include unauthorized access and execution of malicious scripts with root privileges.
Which systems are affected by CVE-1999-0690?
CVE-1999-0690 affects HP CDE environments running on HP-UX version 10.
Is there a patch available for CVE-1999-0690?
There is no specific patch for CVE-1999-0690, but remediation involves modifying the PATH variable.