CVE-2000-0702: High severity HPE HP-UX vulnerability
Published Oct 20, 2000
·Updated
The net.init rc script in HP-UX 11.00 (S008net.init) allows local users to overwrite arbitrary files via a symlink attack that points from /tmp/stcp.conf to the targeted file.
Affected Software
1 affected component
HPE HP-UX=11.00
Remediation
Patch Available
Event History
Oct 20, 2000
CVE Published
04:00 AM
Jan 22, 2001
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-0702?
CVE-2000-0702 is considered a medium severity vulnerability due to its potential for local privilege escalation.
2
How does CVE-2000-0702 impact HP-UX 11.00 users?
CVE-2000-0702 allows local users to overwrite arbitrary files, which can lead to unauthorized access or system compromise.
3
How do I fix CVE-2000-0702?
To fix CVE-2000-0702, ensure that permissions on the /tmp directory are correctly set to prevent symlink attacks.
4
Is CVE-2000-0702 specific to any version of HP-UX?
Yes, CVE-2000-0702 specifically affects HP-UX version 11.00.
5
What is a symlink attack related to CVE-2000-0702?
A symlink attack involves creating a symbolic link in /tmp that redirects to sensitive files, allowing unauthorized modifications.