First published: Fri Oct 20 2000(Updated: )
The net.init rc script in HP-UX 11.00 (S008net.init) allows local users to overwrite arbitrary files via a symlink attack that points from /tmp/stcp.conf to the targeted file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HPE HP-UX | =11.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0702 is considered a medium severity vulnerability due to its potential for local privilege escalation.
CVE-2000-0702 allows local users to overwrite arbitrary files, which can lead to unauthorized access or system compromise.
To fix CVE-2000-0702, ensure that permissions on the /tmp directory are correctly set to prevent symlink attacks.
Yes, CVE-2000-0702 specifically affects HP-UX version 11.00.
A symlink attack involves creating a symbolic link in /tmp that redirects to sensitive files, allowing unauthorized modifications.