CVE-1999-1146: High severity HPE HP-UX vulnerability
Vulnerability in Glance and gpm programs in GlancePlus for HP-UX 9.x and earlier allows local users to access arbitrary files and gain privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
GlancePlus (Glance and gpm)from your environment.Uninstall GlancePlus or remove/disable the vulnerable Glance and gpm programs on affected HP-UX 9.x and earlier systems if they are not required.
- Compensating control
Until the vulnerable software is removed or a vendor patch is available, limit local user exposure by restricting or disabling unneeded local accounts and using host-based access controls (restrict shell access, limit logins) to reduce the ability of local users to exploit the vulnerability.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1146?
CVE-1999-1146 is considered a high severity vulnerability due to its potential to allow local users to access arbitrary files and escalate privileges.
How do I fix CVE-1999-1146?
To fix CVE-1999-1146, it is recommended to upgrade to a later version of HP-UX that is not affected by this vulnerability.
Who is affected by CVE-1999-1146?
CVE-1999-1146 affects users of HP-UX versions 9.x and earlier, as well as version 8.
What programs are impacted by CVE-1999-1146?
CVE-1999-1146 impacts the Glance and gpm programs within GlancePlus for HP-UX.
Can CVE-1999-1146 be exploited remotely?
CVE-1999-1146 is a local privilege escalation vulnerability and cannot be exploited remotely.