CVE-1999-1144: High severity HPE HP-UX vulnerability
Certain files in MPower in HP-UX 10.x are installed with insecure permissions, which allows local users to gain privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Review all files installed by MPower on HP-UX 10.x and correct their ownership and filesystem modes to eliminate insecure permissions that allow local privilege escalation. Remove unnecessary write or execute permissions for unprivileged users and clear any unnecessary setuid/setgid bits; set ownership and modes to the minimum required for correct operation.
MPower (HP-UX 10.x) installed file permissions = secure ownership and file modes; remove insecure permissions
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1144?
CVE-1999-1144 is considered a high severity vulnerability due to the potential for local privilege escalation.
How do I fix CVE-1999-1144?
To fix CVE-1999-1144, you should adjust the file permissions of the affected files in MPower to restrict access.
Who is affected by CVE-1999-1144?
CVE-1999-1144 affects local users on HP-UX versions 10.00, 10.01, 10.10, and 10.20.
What type of vulnerability is CVE-1999-1144?
CVE-1999-1144 is a local privilege escalation vulnerability due to insecure file permissions.
Can CVE-1999-1144 be exploited remotely?
CVE-1999-1144 cannot be exploited remotely as it requires local access to the affected HP-UX systems.