CVE-2001-0488: Low severity HPE HP-UX vulnerability
Published Jun 27, 2001
·Updated
pcltotiff in HP-UX 10.x has unnecessary set group id permissions, which allows local users to cause a denial of service.
Affected Software
4 affected components
HPE HP-UX=10.01
HPE HP-UX=10.26
HPE HP-UX=10.20
HPE HP-UX=10.10
Remediation
Patch Available
Event History
Jun 27, 2001
CVE Published
04:00 AM
Sep 18, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0488?
CVE-2001-0488 is considered a moderate severity vulnerability that may lead to a denial of service.
2
How do I fix CVE-2001-0488?
To fix CVE-2001-0488, remove the unnecessary set group id permissions from the pcltotiff executable.
3
Who is affected by CVE-2001-0488?
CVE-2001-0488 affects local users on HP-UX versions 10.01, 10.10, 10.20, and 10.26.
4
What can an attacker do with CVE-2001-0488?
An attacker can exploit CVE-2001-0488 to cause a denial of service for local system users.
5
When was CVE-2001-0488 discovered?
CVE-2001-0488 was disclosed in 2001, highlighting a problem with permissions in HP-UX.