First published: Tue Jan 09 2001(Updated: )
registrar in the HP resource monitor service allows local users to read and modify arbitrary files by renaming the original registrar.log log file and creating a symbolic link to the target file, to which registrar appends log information and sets the permissions to be world readable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HPE HP-UX | =10.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-1127 is classified as a local privilege escalation vulnerability.
To mitigate CVE-2000-1127, restrict permissions on the registrar.log file to prevent unauthorized access.
CVE-2000-1127 affects HP-UX version 10.20.
No, CVE-2000-1127 requires local access to exploit.
Exploitation of CVE-2000-1127 can lead to unauthorized access to sensitive files.