CVE-1999-1161: High severity HPE HP-UX vulnerability
Vulnerability in ppl in HP-UX 10.x and earlier allows local users to gain root privileges by forcing ppl to core dump.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
ppl (HP-UX)from your environment.Uninstall or remove the ppl binary from systems where it is not required to eliminate the vulnerable component.
- Configuration
Disable core dumps for users who can run ppl to prevent an attacker from forcing a core dump (for example, set ulimit -c 0 in relevant shell profiles or service startup scripts).
ppl (HP-UX) core dump generation (ulimit -c) = 0 (disabled) - Compensating control
Restrict who can execute or access ppl on affected HP-UX 10.x and earlier systems (use file permissions, ACLs, or local access controls) so untrusted local users cannot trigger the vulnerability.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1161?
CVE-1999-1161 has a high severity level because it allows local users to gain root privileges.
How do I fix CVE-1999-1161?
To fix CVE-1999-1161, update your HP-UX system to a version later than 10.x.
Who is affected by CVE-1999-1161?
CVE-1999-1161 affects local users of HP-UX versions 10.x and earlier, including HP-UX 9.
What are the potential impacts of CVE-1999-1161?
The potential impacts of CVE-1999-1161 include unauthorized access to the system with root privileges, leading to complete control over the machine.
Is CVE-1999-1161 exploitable remotely?
CVE-1999-1161 is not remotely exploitable; it requires local access to the affected system.