First published: Mon Sep 01 1997(Updated: )
Character-Terminal User Environment (CUE) in HP-UX 11.0 and earlier allows local users to overwrite arbitrary files and gain root privileges via a symlink attack on the IOERROR.mytty file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HPE HP-UX | <=11.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1139 is considered critical due to its potential to allow local users to gain root privileges.
To mitigate CVE-1999-1139, remove or restrict permissions on the IOERROR.mytty file and consider upgrading to a later version of HP-UX.
CVE-1999-1139 affects local users on HP-UX 11.0 and earlier versions.
CVE-1999-1139 involves a symlink attack that allows users to overwrite arbitrary files.
CVE-1999-1139 cannot be exploited remotely as it requires local user access to the system.