First published: Thu Feb 17 2000(Updated: )
HP Ignite-UX does not save /etc/passwd when it creates an image of a trusted system, which can set the password field to a blank and allow an attacker to gain privileges.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HPE HP-UX | =11.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0159 is considered high severity due to the potential for privilege escalation.
To fix CVE-2000-0159, ensure that HP Ignite-UX is updated to a version that properly handles the /etc/passwd file.
CVE-2000-0159 affects HP-UX version 11.00.
The risks of CVE-2000-0159 include unauthorized access to systems due to blank password fields.
A potential workaround for CVE-2000-0159 is to manually restore the /etc/passwd file after creating an image with HP Ignite-UX.