CVE-2000-0972: Medium severity HPE HP-UX vulnerability
Published Dec 19, 2000
·Updated
HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target file during the crontab session, quitting the session, and reading the error messages that crontab generates.
Affected Software
2 affected components
HPE HP-UX=11.00
HPE HP-UX=10.20
Event History
Dec 19, 2000
CVE Published
via NVD·05:00 AM
Jan 22, 2001
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-0972?
CVE-2000-0972 is considered to be of medium severity as it allows local users to read arbitrary files.
2
How do I fix CVE-2000-0972?
To fix CVE-2000-0972, ensure that proper permissions are set on crontab files and restrict the use of the -e option for unprivileged users.
3
Who is affected by CVE-2000-0972?
CVE-2000-0972 affects users of HP-UX versions 10.20 and 11.00.
4
What is the main exploit method for CVE-2000-0972?
The main exploit method for CVE-2000-0972 involves creating a symlink to access arbitrary files during a crontab session.
5
Is CVE-2000-0972 a local or remote vulnerability?
CVE-2000-0972 is a local vulnerability that can only be exploited by local users.