CVE-1999-1133: Medium severity HPE HP-UX vulnerability
HP-UX 9.x and 10.x running X windows may allow local attackers to gain privileges via (1) vuefile, (2) vuepad, (3) dtfile, or (4) dtpad, which do not authenticate users.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
vuefilefrom your environment.If not required, uninstall or remove the vuefile binary from HP-UX 9.x and 10.x systems to eliminate this attack vector.
- Remove
Remove
vuepadfrom your environment.If not required, uninstall or remove the vuepad binary from HP-UX 9.x and 10.x systems to eliminate this attack vector.
- Remove
Remove
dtfilefrom your environment.If not required, uninstall or remove the dtfile binary from HP-UX 9.x and 10.x systems to eliminate this attack vector.
- Remove
Remove
dtpadfrom your environment.If not required, uninstall or remove the dtpad binary from HP-UX 9.x and 10.x systems to eliminate this attack vector.
- Configuration
If X Window is not required on HP-UX 9.x or 10.x systems, disable or stop the X Window service to prevent local attackers from exploiting vuefile, vuepad, dtfile, or dtpad.
X Window System (HP-UX) enabled = disabled - Compensating control
Limit local interactive access (console, local logins) to trusted administrators and auditors on HP-UX 9.x and 10.x systems to reduce the risk posed by local-only privilege escalation via these X Window programs.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1133?
CVE-1999-1133 is considered a high severity vulnerability due to its potential for privilege escalation by local attackers.
How do I fix CVE-1999-1133?
To fix CVE-1999-1133, ensure that the vulnerable applications vuefile, vuepad, dtfile, and dtpad are updated or secured to enforce user authentication.
Who is primarily affected by CVE-1999-1133?
CVE-1999-1133 primarily affects users of HP-UX 9.x and 10.x systems running X windows.
What are the implications of CVE-1999-1133?
The implications of CVE-1999-1133 include the risk of unauthorized users gaining elevated privileges on the affected systems.
Is CVE-1999-1133 still a concern today?
While CVE-1999-1133 is an older vulnerability, it may still pose a concern for legacy systems that have not been updated or are still in use.