CVE-1999-1089: Buffer Overflow
Buffer overflow in chfn command in HP-UX 9.X through 10.20 allows local users to gain privileges via a long command line argument.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
HP-UX chfnfrom your environment.If chfn is not required on affected HP-UX 9.X through 10.20 systems, remove or disable the chfn binary to prevent local privilege escalation via long command-line arguments.
- Compensating control
Until an official vendor fix is available, restrict which local accounts can execute chfn (for example, remove/limit execute permission on the chfn binary or restrict access via filesystem permissions/ACLs) and limit interactive/local user access to trusted administrators only.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1089?
CVE-1999-1089 is considered a high severity vulnerability due to its potential for local privilege escalation.
How do I fix CVE-1999-1089?
To fix CVE-1999-1089, apply the latest patches provided by HPE for HP-UX versions 9.X through 10.20.
What systems are affected by CVE-1999-1089?
CVE-1999-1089 affects HP-UX versions 9 through 10.20.
What type of vulnerability is CVE-1999-1089?
CVE-1999-1089 is classified as a buffer overflow vulnerability.
Can CVE-1999-1089 be exploited remotely?
CVE-1999-1089 cannot be exploited remotely as it requires local access to the system.