CVE-2001-1256: Low severity HPE HP-UX vulnerability
Published Jun 11, 2001
·Updated
kmmodreg in HP-UX 11.11, 11.04 and 11.00 allows local users to create arbitrary world-writeable files via a symlink attack on the (1) /tmp/.kmmodreglock and (2) /tmp/kmpath.tmp temporary files.
Affected Software
3 affected components
HPE HP-UX=11.11
HPE HP-UX=11.04
HPE HP-UX=11.00
Remediation
Patch Available
Event History
Jun 11, 2001
CVE Published
04:00 AM
May 3, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1256?
CVE-2001-1256 is considered a low severity vulnerability, primarily affecting local users.
2
How do I fix CVE-2001-1256?
To fix CVE-2001-1256, restrict permissions on the affected temporary files to prevent unauthorized creation of symlinks.
3
What systems are affected by CVE-2001-1256?
CVE-2001-1256 affects HP-UX versions 11.00, 11.04, and 11.11.
4
What type of attack does CVE-2001-1256 involve?
CVE-2001-1256 involves a symlink attack allowing local users to create arbitrary world-writable files.
5
Can CVE-2001-1256 be exploited remotely?
No, CVE-2001-1256 can only be exploited by local users on the affected systems.